Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Azure Payment HSM v2 uses private endpoints to keep management and payment-application traffic on private IP addresses. This article describes private endpoint configuration, Domain Name System (DNS) setup, required ports, network security group (NSG) rules, and virtual machine (VM) placement.
Public network access
Azure Payment HSM v2 is designed to be reached only over private connectivity. Deploy the cluster with public network access disabled so that all traffic reaches the HSM through private endpoints rather than the public internet.
Private endpoints depend on the AllowPrivateEndpoints feature. During preview, Azure doesn't register this capability automatically. Register the AllowPrivateEndpoints feature for the Microsoft.Network resource provider on each subscription where you deploy the service before you create the networking resources. If you don't register the feature, the private endpoint steps fail.
- Deploy the cluster with
publicNetworkAccessset toDisabled. For more information, see Create a Payment HSM v2 instance. - Register the
AllowPrivateEndpointsfeature on each subscription. For more information, see Register the AllowPrivateEndpoints feature.
Private endpoint
Azure Payment HSM v2 exposes two Azure Private Link target subresources: management on port 7005 and application on port 2200. Create a separate private endpoint for each interface in the appropriate client subnet. Private endpoints provide private IP addresses for connections from your virtual network and supported hybrid networks.
Traffic between your virtual network and Azure Payment HSM v2 doesn't traverse the public internet. This private connectivity reduces internet exposure.
For deployment instructions, see Create a private endpoint for Azure Payment HSM v2.
Private DNS
When you create the management and application private endpoints, Azure Payment HSM v2 assigns each HSM node a private DNS hostname for each interface in the following format:
Management port: 7005 - Administrative and management operations.
mgmt1.<pool-name>-<unique-string>.privatelink.phsm.azure.net
Application port: 2200 - Payment application data plane for Atalla commands and cryptographic operations.
app1.<pool-name>-<unique-string>.privatelink.phsm.azure.net
To resolve these hostnames from your virtual network, configure a private DNS zone for privatelink.phsm.azure.net and link it to the virtual networks that contain your admin and application VMs. Associate each private endpoint with the private DNS zone by using a private DNS zone group.
Required ports
Azure Payment HSM v2 uses the following ports. Allow outbound TCP traffic from each client subnet to the corresponding private endpoint IP address.
| Port | Direction | Client | Purpose |
|---|---|---|---|
| 7005 | Outbound (client → management endpoint) | Utimaco Secure Configuration Assistant (SCA) and C3 Key Loading Device (KLD) | Management port for administrative and management operations. |
| 2200 | Outbound (client → application endpoint) | Payment application | ASCII port for Atalla commands and cryptographic operations. |
NSG rules
When you deploy admin and application VMs in subnets with NSGs, add an outbound rule to each NSG for the corresponding private endpoint and port. For example:
| Priority | Name | Source | Destination | Port | Protocol | Action |
|---|---|---|---|---|---|---|
| 100 | Allow-PHSM-Management |
VirtualNetwork |
<management-private-endpoint-IP> |
7005 | TCP | Allow |
| 110 | Allow-PHSM-Application |
VirtualNetwork |
<application-private-endpoint-IP> |
2200 | TCP | Allow |
Replace each destination placeholder with the private IP address assigned to the corresponding Payment HSM v2 private endpoint. Apply each rule only to the NSG associated with the client subnet that needs access to that interface.
VM placement
Create an Azure VM in a virtual network that can connect to the management private endpoint. Use the VM to run Utimaco SCA for initial HSM setup, user management, key management, and backup operations.
For a deployment example, see Quickstart: Create a Linux VM in the Azure portal.
The admin VM requires network connectivity to the management private endpoint.
Tip
Place Payment HSM v2 resources in a separate resource group from the client VMs and virtual network. This separation simplifies lifecycle management and access control.
On-premises connectivity
Use Azure VPN Gateway to establish a virtual private network (VPN) connection between your on-premises network and the virtual network that contains the private endpoints:
- Site-to-site VPN. Use this option for persistent on-premises connectivity. For setup instructions, see Tutorial: Create a site-to-site VPN connection in the Azure portal.
- Point-to-site VPN. Use this option for individual workstations or smaller deployments. For more information, see About Azure point-to-site VPN connections.
Configure DNS forwarding or Azure DNS Private Resolver so that on-premises clients resolve the HSM hostnames to the private endpoint IP addresses. For supported patterns, see Azure Private Endpoint DNS integration scenarios.