Architecture Assistance - OpenWrt on WRT1200AC and Firebox T15

Objective: Establish a Site to Site VPN to Azure Virtual Network Gateway
ISP: Comcast/Xfinity
Architecture: Netgear CM1200 modem and Linksys WRT1200AC v1 running OpenWRT 21.02.1 (and stock firmware on the other partition)
Problem: After countless hours of effort, I was unable to fully establish the S2S VPN using the WRT1200AC running OpenWRT. There just doesn't appear to be current and accurate OpenWRT v21 documentation.
Plan: I have acquired a WatchGuard Firebox T15 for no cost. I now plan to use this appliance for the S2S VPN while maintaining my WRT1200AC as my wireless access point.
Question: Which device should connect to the Netgear modem? My preference is the WRT1200AC (and I have a Watchguard drawing to support this, but it provides no details). I am asking here to get the perspective of an OpenWRT guru.
If you agree with my preference, can you provide a recommendation for the WRT1200AC configuration changes?
If you disagree, please explain.
Thanks in Advance.

The Plan changed. I ended up connecting the Firebox T15 to the Netgear modem and then the Linksys WRT1200AC to the T15 as my wireless access point. The T15 makes it much easier to establish a Site to Site tunnel to Azure.