With virtual network service tunneling, all your external traffic is forced to go through a site-to-site VPN tunnel. Without this, external traffic will always go directly from Azure to the internet. This gives you the opportunity to audit the traffic.
Forced tunneling uses the UDRs to define the routing. Instead of choosing the virtual appliance, you now choose the virtual network gateway: