For two managed instances to participate in a failover group, there must be either ftoute or a gateway configured between the virtual networks of the two managed instances to allow network communication. You create the two VPN gateways and connect them. Create the gateway for the virtual network of your primary managed instance using the Azure portal. Create the gateway for the virtual network of your secondary managed instance using the Azure portal. Create a bidirectional connection between the two gateways of the two virtual networks. Reference: https://docs.microsoft.com/en-us/azure/azure-sql/managed-instance/failover-group-add-instance-tutorial?tabs=azure-portal#4---create-a-primary-gateway