Hi Ajay,
The way you establish VPN is by using a dedicated subnet with an internet gateway that will NAT the CSRs public facing interface to a public IP address. You would then use the public IP address to establish VPN tunnels
Please see deployment guide here https://supportforums.cisco.com/document/12744996/cisco-csr-1000v-deployment-guide-microsoft-azure