Route Table settings to allow Traffic via S2SVPN to Azure via NVA

I`ve set up the Route Table to allow Traffic from S2SVPN to Azure via NVA.

However, the traffic goes direct.

Kindly confirm :

a) for TO & FRO of traffic do I need 2 Route Table (one for Incoming and one for Outgoing)

b) HOw to verify if the UDR settings are correct?

c) Force Tunnelling as also enabled, does that impacts UDR rules?

Any assistance will be deeply appreciated.

Thanks in advance.

