The VMs are in AZ then VPN gateway will have to on AZ which will rely on Azure public IP resource Standard SKU. And must be Static as Dynamic is only for non-AZ. Reference: https://learn.microsoft.com/en-us/azure/virtual-network/ip-services/public-ip-addresses#at-a- glance https://learn.microsoft.com/en-us/azure/vpn-gateway/about-zone-redundant-vnet-gateways