Hello Qiu, Horus,Thanks for your question.
This is expected. NSGs in Azure do not apply to the load balancer frontend IP address.NSG can be associated with either subnets or individual VM instances within that subnet, so we can’t use NSG to block inbound IP address from the internet.See:
How network security groups filter network traffic
Please let me know if you have further questions.
You can mark it 'Accept Answer' if this helped you