Additional Network Gateway at separate location?

We successfully run a Access Gateway and Network Gateway to protect web applications that run on-premise. Both, DAG and DNG are part of our DMZ.

Now, we’d like to protect a web application that is hosted on a cloud server. Deploying a separate NG is no problem; but can it be successfully linked to the DAG in our DMZ via its publically reachable addresses?