
Explanation:
< From the Azure portal: Enable IP forwarding for NIC1.
On VM1: Install and configure Routing and Remote Access
In Azure VNets, layer-3 routing between subnets is provided by the platform, but if you want a VM to act as a router (NVA) and forward traffic between subnets, two things are required: the NIC must be allowed to pass traffic not destined to itself, and the guest OS must be configured to perform IP forwarding/routing. The Administering Windows Server Hybrid Core Infrastructure guidance for "Manage and maintain Windows Server IaaS virtual machines" and "Implement on-premises and hybrid networking" explains that Azure requires IP forwarding to be enabled on the NIC for any VM acting as a router or load balancer so that the fabric will deliver transit packets to the VM instead of dropping them. The Windows Server role that provides routing is Routing and Remote Access (RRAS); enabling the LAN routing feature configures the TCP/IP stack to forward packets between interfaces (including forwarding back out the same interface when used with Azure's virtual switch). The same material notes that adding extra NICs is not mandatory for simple transit scenarios, and that user-defined routes can be used when you need to steer traffic through the router; however, to enable the VM itself to route, the minimal administrative steps are: turn on IP forwarding for the NIC in Azure and install/configure RRAS in the guest. This combination allows VM1 to route traffic between Subnet1 and Subnet3 with the least effort.