Hi @ DONG CHEN,
Welcome to Microsoft Q&A Platform.
From an Azure VM (eden4) we see TCP SYNs/ICMP targeted at our on-prem IP 192.xxx.233:13202, and Network Watcher connection troubleshoot shows next-hop = MicrosoftEdge but Connectivity test: Unreachable (probes 30/30 failed).
Please check the CE/router for VLAN and ARP for Azure private peering IPs (169.xxx.xxx.xxx), confirm CE receives the packets from Azure and forwards them to 192.xxx.233. Also capture traffic on the CE for that time window.
Please Verify BGP session is established, and provider is not filtering the prefixes or the port.
You can use the Test private peering connectivity tool in the Azure portal to validate packet flow between your on-premises network and Azure resources and also run the PsPing utility to assess connectivity from your on-premises IP to the Azure IP addresses
Ref: Verify ExpressRoute connectivity and Verify ExpressRoute connectivity
Kindly let us know if the above helps or you need further assistance on this issue.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.