Edit

Network security for Azure Payment HSM v2

Azure Payment HSM v2 uses private endpoints to keep management and payment-application traffic on private IP addresses. This article describes private endpoint configuration, Domain Name System (DNS) setup, required ports, network security group (NSG) rules, and virtual machine (VM) placement.

Public network access

Azure Payment HSM v2 is designed to be reached only over private connectivity. Deploy the cluster with public network access disabled so that all traffic reaches the HSM through private endpoints rather than the public internet.

Private endpoints depend on the AllowPrivateEndpoints feature. During preview, Azure doesn't register this capability automatically. Register the AllowPrivateEndpoints feature for the Microsoft.Network resource provider on each subscription where you deploy the service before you create the networking resources. If you don't register the feature, the private endpoint steps fail.

Private endpoint

Azure Payment HSM v2 exposes two Azure Private Link target subresources: management on port 7005 and application on port 2200. Create a separate private endpoint for each interface in the appropriate client subnet. Private endpoints provide private IP addresses for connections from your virtual network and supported hybrid networks.

Traffic between your virtual network and Azure Payment HSM v2 doesn't traverse the public internet. This private connectivity reduces internet exposure.

For deployment instructions, see Create a private endpoint for Azure Payment HSM v2.

Private DNS

When you create the management and application private endpoints, Azure Payment HSM v2 assigns each HSM node a private DNS hostname for each interface in the following format:

Management port: 7005 - Administrative and management operations.

  • mgmt1.<pool-name>-<unique-string>.privatelink.phsm.azure.net

Application port: 2200 - Payment application data plane for Atalla commands and cryptographic operations.

  • app1.<pool-name>-<unique-string>.privatelink.phsm.azure.net

To resolve these hostnames from your virtual network, configure a private DNS zone for privatelink.phsm.azure.net and link it to the virtual networks that contain your admin and application VMs. Associate each private endpoint with the private DNS zone by using a private DNS zone group.

Required ports

Azure Payment HSM v2 uses the following ports. Allow outbound TCP traffic from each client subnet to the corresponding private endpoint IP address.

Port Direction Client Purpose
7005 Outbound (client → management endpoint) Utimaco Secure Configuration Assistant (SCA) and C3 Key Loading Device (KLD) Management port for administrative and management operations.
2200 Outbound (client → application endpoint) Payment application ASCII port for Atalla commands and cryptographic operations.

NSG rules

When you deploy admin and application VMs in subnets with NSGs, add an outbound rule to each NSG for the corresponding private endpoint and port. For example:

Priority Name Source Destination Port Protocol Action
100 Allow-PHSM-Management VirtualNetwork <management-private-endpoint-IP> 7005 TCP Allow
110 Allow-PHSM-Application VirtualNetwork <application-private-endpoint-IP> 2200 TCP Allow

Replace each destination placeholder with the private IP address assigned to the corresponding Payment HSM v2 private endpoint. Apply each rule only to the NSG associated with the client subnet that needs access to that interface.

VM placement

Create an Azure VM in a virtual network that can connect to the management private endpoint. Use the VM to run Utimaco SCA for initial HSM setup, user management, key management, and backup operations.

For a deployment example, see Quickstart: Create a Linux VM in the Azure portal.

The admin VM requires network connectivity to the management private endpoint.

Tip

Place Payment HSM v2 resources in a separate resource group from the client VMs and virtual network. This separation simplifies lifecycle management and access control.

On-premises connectivity

Use Azure VPN Gateway to establish a virtual private network (VPN) connection between your on-premises network and the virtual network that contains the private endpoints:

Configure DNS forwarding or Azure DNS Private Resolver so that on-premises clients resolve the HSM hostnames to the private endpoint IP addresses. For supported patterns, see Azure Private Endpoint DNS integration scenarios.