For Site-to-Site VPNs, the exam guide states that "the on-premises address spaces and the Azure virtual network address spaces must not overlap." Overlapping prefixes prevent route advertisement and creation of connections. Your on-premises network uses 10.0.0.0/23, which spans 10.0.0.0-10.0.1.255. The current VNet1 space is 10.0.1.0/24, which sits inside the on-premises supernet and therefore overlaps. The guidance instructs: "Before configuring gateways and connections, ensure VNet address ranges are unique and non- overlapping with any local networks." Options like deploying Bastion or Azure Extended Network don't change IP topology and won't resolve the overlap. Subnetting VNet1 to 10.0.1.128/25 also still overlaps the 10.0.0.0/23 range. The correct first step is to change VNet1's address space to a non-overlapping range, such as 10.0.2.0/24, and then proceed to deploy the virtual network gateway and the S2S connection. This aligns with the required prerequisite in the study material that unique address spaces are mandatory for successful S2S VPN routing.