hi Ravi Kumar Shanker & thx for sharing urs issue here at Q&A portal,
ur understanding is correct. In Azure VMware Solution, the Tier-0 Gateway is Microsoft-managed, so customers can't create or modify Tier-0 VRFs themselves. If VRF Tier-0 Gateways are needed, that has to be coordinated through Microsoft support.
VRFs are intended to provide routing separation, but whether they achieve your exact traffic flow (forcing Production <-> DMZ traffic through ExpressRoute, Virtual WAN, and Azure Firewall) depends on the supported AVS routing design. I wouldn't assume that simply placing the T1s under different VRFs automatically forces traffic out to MSEE instead of routing internally.
Given your constraints (no vDefend, no third-party NVA, no second SDDC), I'd recommend engaging the AVS networking team through a support case. They can confirm whether the proposed VRF design is supported and whether inter-VRF traffic can be steered through Azure Firewall as you described. The AVS networking https://learn.microsoft.com/azure/azure-vmware/concepts-networking I'd include your current topology (T0, T1s, ExpressRoute, Virtual WAN, Azure Firewall) in the support request. This is more of an architecture validation than a configuration question, and the AVS team can confirm whether VRF-based isolation is the right approach or if there's another supported design.
rgds,
Alex
&
If my answer was helpful pls mark it and additional thx if u follow me at Q&A portal
and at my blog https://ctrlaltdel.blog/