Can you explain a little more please, or if possible post a diagram?
Hair-pinning to security device? kindly share more info.
Yes, that is the default behavior in HCX. The default gateway for all VMs connected to the extended network remains on-prem.
As @t0mzukowski says this is the default behaviour for HCX and this is clear in the documentation.
Please can you explain if your scenario is different or clarify what your concerns are?
