Tutorial: Use a VPN to access the payShield manager for your payment HSM

After you Create an Azure Payment HSM, you can connect to its payShield manager through your browser.

To connect to payShield manager, you need to have an on-premises, standard PC with a supported web-browser, together with the USB connected payShield Manager Reader and payShield Manager smart cards. Users connect to the payShield 10K via HTTP(s) using a configured management NIC IP address.

You need a minimum of five smart cards (three cards for a CTA set, a Left Key Card and a Right Key Card) and one reader. See Thales's payShield 10K Installation and User Guide for the detailed instructions.

Sample deployment scenarios

Here are two sample scenarios for connecting to payShield manager for your payment HSM.

Sample deployment 1:

An architecture diagram of a sample deployment, allowing you to access the payShield manager for your payment HSM.

Sample deployment 2:

An architecture diagram of an alternative, sample deployment, allowing you to access the payShield manager for your payment HSM.

To access payShield manager from your on-premises PC, directly connect to HSMMgmtNic private IP address (10.1.0.4)

A screenshot showing a successful connection to the payShield manager through a browser.

Next steps

When you can access payShield Manager, proceed to the steps for HSM commissioning, HSM configuration, and loading LMKs:

  1. Install the smart card reader driver.
  2. Install the Thales browser extension and local application component.
  3. Commission your payShield.
  4. Do the initial configuration steps.
  5. Generate and install LMKs.
  6. Test the API.

Please follow Thales’s payShield 10K Installation and User Guide for the detailed instructions, and contact Thales support if there are any issues.

Microsoft maintains a base firmware across the fleet, you can check the base firmware version from the HSM allocated, or check the support guide. You must upgrade the firmware based on your requirements.

More resources: