Thank you Vikas,
Sorry just to clarify this - "2: It's not mandatory to have new interface with public IP on the SSG. You can use any IP/Interface which has reachablity to the Azure cloud."
Does this mean I can use the same SSG tunnel interface and ip-address for both the existing VPN tunnel (policy-based) and new VPN tunnel (route-based) ? Sorry, in my mind it won't work but I'm probably wrong.