Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.
I understand that you would like to know if there are any alternatives to make the opened ports of Azure VPN Gateway inaccessible.
- Unfortunately, this is not feasible.
- The ports are in listening state so that the platform can access it via these ports. If we were to block it using Azure Firewall or NSG, that would not help the case.
- The documents and reference Q&A threads shared by you are correct.
This is by design of the product and we cannot override this.
Also, see : Gateway subnet considerations
Thanks,
Kapil
Please Accept an answer if correct. Original posters help the community find answers faster by identifying the correct answer.