Azure Private Endpoint - Listening restrictions

I'm experiencing some deeply frustrating issues when trying to connect to a SQL server Private Endpoint. Setting aside for a moment a complete specification of the problem, I'd like answers to the following questions


1. Is it the case that a SQL Server Private Endpoint will only listen to connections from an Azure Virtual Machine?  I have seen it suggested by 3rd parties that this is the case but cannot find this explicitly documented by MS. (To clarify, if only VMs can connect, then this would mean, for example, that an Azure Load Balancer could not use Private Endpoint as a backend resource; and, for example, that an on-premise VM could not connect to a Private Endpoint through a VPN - is that correct?)


2. Presuming the answer to the above question is Yes, then does the restriction apply such as to prevent Private Endpoint from listening to connections forwarded from an Azure VM interface?

(For example, say a firewall in a VM in Azure. Inside the firewall VM, the IP is configured. In Azure, the VM interface is associated with only a single IP address which is IP    In this scenario, the firewall VM will respond to ARP requests with ARP responses saying "I have", but is not associated by Azure configuration with any Azure virtual network interface.  In said case, will a connection to the Private Endpoint using source address work?   Or is it the case that the PE will listen for connections only with a source address



