on site 1 router you nead add ipsec policy witch dst net of azure and the reverse to site 2
nat it is not necessary if you set correct routing in azure
Thank you very much for your response.
That is the logical solution, but I cannot implement it because I don’t control Azure, GCP, or the other offices, so I have to use the output already established by Site2.
Could I use a NAT at Site2 so that when something destined for Azure comes in, it changes the address to the LAN used to connect to Azure?