RD Gateway uses only NTLM by design. In order to use Kerberos the rd client as well as the machine being remoted into, both need to be able to communicate with the kerberos server (DC). If they can both do that, then they could just RDP without the need for an RD Gateway and it is now pointless to have.
This is why we are switching to using the MS always on VPN (the successor to direct access).
We are phasing out NTLM from our network and therefore phasing our RDGW. This is more resilient and allows us to apply policies to the remote computer,