Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Azure Private Link enables you to access Azure services, such as Azure Cloud HSM, Azure Key Vault, and Azure Storage, over a private endpoint in your virtual network. An Azure private endpoint is a network interface that uses a private IP address from your virtual network, effectively bringing the service into your virtual network. Traffic between your virtual network and Azure Cloud HSM traverses the Microsoft backbone network, so exposure from the public internet is eliminated.
For more information about Private Link, see What is Azure Private Link?.
Azure Cloud HSM supports connectivity exclusively through Private Link. Every Cloud HSM cluster is reached through a private endpoint that you create in a subnet of your virtual network; there's no public endpoint for the data plane. This article describes how the integration works and how to establish, verify, and manage a private link connection to Azure Cloud HSM.
Prerequisites
To integrate an Azure Cloud HSM cluster with Azure Private Link, you need:
- An Azure subscription that's approved for Azure Cloud HSM. If you don't have one, see the Azure Cloud HSM onboarding guide.
- An Azure virtual network and a dedicated subnet for the private endpoint.
- Owner or contributor permissions on both the resource group that contains the Cloud HSM cluster and the virtual network.
- The required client ports allowed by any network security groups (NSGs) or firewalls between your client VMs and the private endpoint subnet.
Your private endpoint and virtual network must be in the same Azure region. The Cloud HSM cluster can be in a different region from the virtual network, as long as the virtual network has connectivity to the private endpoint's region.
Each Azure Cloud HSM cluster consists of three HSM nodes that are reached through a single private endpoint. For more information about the cluster architecture, see What is Azure Cloud HSM?.
How Private Link integration works
When you deploy an Azure Cloud HSM cluster, the service creates a Private Link resource that represents the cluster's data plane. You associate that Private Link resource with a private endpoint in a subnet of your virtual network. The private endpoint receives a private IP address from the subnet, and each HSM node in the cluster is exposed through a private DNS hostname in the privatelink.cloudhsm.azure.net zone:
hsm1.chsm-<resource-name>-<unique-string>.privatelink.cloudhsm.azure.net
hsm2.chsm-<resource-name>-<unique-string>.privatelink.cloudhsm.azure.net
hsm3.chsm-<resource-name>-<unique-string>.privatelink.cloudhsm.azure.net
Your admin VM and application VMs use the Azure Cloud HSM SDK (azcloudhsm_client and azcloudhsm_mgmt_util) to connect to those hostnames. The client daemon resolves the hostnames to the private endpoint IP address and establishes a mutually authenticated TLS connection to the HSM nodes over ports 2224, 2225, 443, and 444. For the full port list, see Network security for Azure Cloud HSM.
Because there's no public data-plane endpoint, all cryptographic traffic between your workloads and the HSM stays on the Microsoft backbone network.
Establish a private link connection
You create the private endpoint for Azure Cloud HSM as part of deploying the cluster. The Azure portal deployment experience integrates private endpoint creation and private DNS zone integration into the same workflow. When you deploy by using Azure PowerShell, you create the private endpoint during deployment and configure DNS separately.
To create an Azure Cloud HSM cluster and its private endpoint in the Azure portal:
Follow the steps in Deploy Azure Cloud HSM by using the Azure portal through the Basics and Identity tabs.
On the Networking tab, select the subscription, virtual network, and subnet where you want the private endpoint to be created, and configure the private DNS integration settings. For details, see Set up networking.
Keep private DNS zone integration enabled to have the portal automatically create or link the
privatelink.cloudhsm.azure.netprivate DNS zone to your virtual network. If you manage your own DNS, disable this option and configure DNS as described in Manage private DNS.Review and create the cluster. Deployment provisions the HSM cluster, creates the private endpoint in your subnet, and (if selected) links the private DNS zone.
Manage private DNS
Your client VMs must be able to resolve the HSM hostnames in privatelink.cloudhsm.azure.net to the private endpoint's IP address.
- Automatic integration (recommended). When you create the private endpoint through the Azure portal or the Cloud HSM quickstart, keep Integrate with private DNS zone enabled. Azure creates (or reuses) the
privatelink.cloudhsm.azure.netprivate DNS zone, links it to your virtual network, and adds A records for each HSM node. - Custom DNS. If you use your own DNS servers (for example, an on-premises DNS forwarded through Azure DNS Private Resolver), create the
privatelink.cloudhsm.azure.netzone in your DNS solution and add A records that map each HSM hostname to the private endpoint's private IP address. - Hub-and-spoke networks. Link the private DNS zone to every virtual network that hosts a Cloud HSM client. If your topology uses a central hub for DNS, link the zone to the hub virtual network and ensure the spokes forward DNS queries to it.
To verify DNS resolution from a client VM, run:
nslookup hsm1.chsm-<resource-name>-<unique-string>.privatelink.cloudhsm.azure.net
The result must be the private IP address of your Cloud HSM private endpoint. If DNS resolution fails, the azcloudhsm_client and azcloudhsm_mgmt_util tools can't connect to the cluster.
For general guidance on private DNS with Private Link, see Azure Private Endpoint DNS integration.
Configure network security
Because Azure Cloud HSM is reachable only through Private Link, restrict the network path between your client VMs and the private endpoint:
- NSGs. Add outbound NSG rules on your VM subnets to allow TCP traffic to the private endpoint on ports 2224, 2225, 443, and 444. Sample rules are shown in Network security for Azure Cloud HSM.
- Firewalls and user-defined routes. If a network virtual appliance (NVA) or Azure Firewall sits between your VMs and the private endpoint subnet, allow the same ports and make sure user-defined routes don't blackhole traffic to the private endpoint IP.
- On-premises clients. To connect on-premises signing servers or applications, extend your virtual network with a site-to-site or point-to-site VPN, or with Azure ExpressRoute. On-premises clients must run the
azcloudhsm_clientdaemon and reach the HSM private endpoint IP over the private connection. See On-premises connectivity.
Verify the private link connection
After deployment, verify that Private Link is configured correctly:
- Check the private endpoint state. In the Azure portal, open the Cloud HSM cluster, select Networking > Private endpoint connections, and confirm that the connection state is Approved.
- Confirm DNS resolution. From a VM in the linked virtual network, run
nslookupagainst each HSM hostname and confirm the response is the private endpoint IP address. - Test client connectivity. From an admin VM that has the Azure Cloud HSM SDK installed, run
azcloudhsm_mgmt_utiland confirm that it connects to all HSM nodes in the cluster. For end-to-end deployment validation, see Initialize and configure your HSM.
Limitations
- Azure Cloud HSM doesn't expose a public data-plane endpoint. All data-plane traffic must go through a private endpoint.
- A private endpoint and its target Cloud HSM cluster's virtual network must be in the same Azure region.