It appears now with 4.0.0 Enterprise and Java 11 we can bind JMX to a particular address instead of broadcasting it to the world using these settings:
# Remote JMX monitoring, uncomment and adjust the following lines as needed. Absolute paths to jmx....