You need to ensure that users can access VM0. The solution must meet the platform protection requirements.
What should you do?
Move VM0 to Subnet1.
On Firewall, configure a network traffic filtering rule.
Assign RT1 to AzureFirewallSubnet.
On Firewall, configure a DNAT rule.
https://docs.microsoft.com/en-us/azure/firewall/tutorial-firewall-dnat
Submit