WAF and WSUS - possible?

i want to "publish" our WSUS to the internet to reach all those remote workers client which do not connect to the VPN anymore because everything is in the cloud.

As we are not ready to use Windows Update for Business and Intune - i want to perform a small step into "cloud updates".

Is this even possible? Did anyone try it? I've set it up - but nothing happens. - I do not want to use DNAT if possible

