Virtual Network Gateway a.k.a VPN Gateway
Azure VPN Gateway connects your on-premises networks to Azure through Site-to-Site VPNs in a similar way that you set up and connect to a remote branch office. The connectivity is secure and uses the industry-standard protocols Internet Protocol Security (IPsec) and Internet Key Exchange (IKE).
Site-to-site VPN
A Site-to-site (S2S) VPN gateway connection is a connection over IPsec/IKE (IKEv1 or IKEv2) VPN tunnel. S2S connections can be used for cross-premises and hybrid configurations. A S2S connection requires a VPN device located on-premises that has a public IP address assigned to it.
ExpressRoute Gateway
It provides a dedicated, private connection between on-premises infrastructure and Azure data centers.
NAT Gateway
A NAT (Network Address Translation) Gateway in Azure is a service that enables outbound internet connectivity for resources deployed in a virtual network. NAT Gateway provides a static public IP address for resources within the virtual network to communicate with resources outside the network.
In Azure, NAT Gateway is used to translate private IP addresses used by resources within the virtual network to a public IP address that can be accessed over the internet. This allows resources in the virtual network to securely communicate with services outside of the network, such as Azure services, internet resources, or on-premises resources connected via a VPN or ExpressRoute.
Application Gateway is as=as WAF in AWS
Azure Application Gateway is a service that helps manage and scale traffic to multiple web applications running in your Azure virtual network. It acts as a traffic cop, routing requests to the appropriate server based on your defined rules. It can also help improve the performance and security of your web applications.