When you create a virtual network, Azure automatically creates a default route table for each of its subnets and adds system default routes to the table. In this step, you create a user-defined route table that routes all traffic to the firewall, and then associate it with the App Service subnet in the integrated virtual network. Section3 in document. https://learn.microsoft.com/en-us/azure/app-service/network-secure-outbound-traffic-azure- firewall