If you have a vMX in Azure is there a way to be able to ping/poll with ICMP/SNMP without a full IPSEC tunnel to the vMX?
With an MX you can enable SNMP and poll it from the public IP on a WAN interface, in Azure the public is assigned by Azure and the vMX appliance appears to be so locked down you cannot change anything on it nor assign an NSG to it to allow specific rules to it.
I also noticed the vMX has the SNMP configuration but in the firewall page doesnt have the same allow source networks section as the physical MX's do.
Has anyone found a way to allow these specific ports access on the public IP of the vMX in Azure, or is an IPSEC tunnel the only way (then poll the private IP of the vMX)