Thank you for reaching out. Yes, port number 7999 and 8444 is used for Azure infrastructure communication. I am confirming the information regarding port 8010 with the team internally and will get back to you shortly.
As documented here They're protected (locked down) by Azure certificates. Without proper certificates, external entities, including the customers of those gateways, won't be able to cause any effect on those endpoints. The public endpoints are periodically scanned by Azure security audit.
Update 07/11: Based on our private conversation here. We are disregarding the information regarding port 8010.
For community benefit port 8010 should not be open on Azure VPN Gateway.
Thank you!