To allow RDP requests to reach VM1 through the public IP of FW1, you need to create a rule that translates the destination IP address of the incoming RDP requests to the private IP address of VM1. This is done through a type of rule called a DNAT rule, which is configured on the Azure Firewall Policy (FP1). Other types of rules, such as network rules, URL filtering, and application rules, are not relevant to this specific scenario. https://learn.microsoft.com/en-us/azure/firewall/tutorial-firewall-dnat-policy