Hi Bryce, I've set a few of the up for some customers I work with, on the most recent ones I've normally added an NSG for the vMX subnet and allowed inbound traffic on UDP 500 and 4500 for client VPN or 443 (or selected custom port) for AnyConnect. To be honest most of the recent deployments have used AnyConnect, so I'm not sure if there has been any changes which require additional configuration for Client VPN, but a quick thing to try anyway. You may also want to add a NSG rule to allow ICMP in for testing PINGs. A simple way to check if this has worked is to check the Event Log for the vMX for Client VPN or AnyConnect entries
... View more