Documentation

Merchant Configuration Guide

Domain – Primary Site & Secondary Site IP Setup for MAX Availability

1. Why — Background and Impact

NTT Data Payment Services India is introducing a Blue-Green (BG) & active-active architecture to maximize availability for our payment platform. Unlike a standby/failover setup, active-active means both regions — including a new Site 2-based region — serve live production traffic at the same time. Individual transactions will be dynamically routed to whichever region balances system load, rather than always going through a single fixed path.

To support this, merchants need to allow their systems to reach a secondary connection path routed via the Site 2 based region, in addition to the existing primary connection (payment.atomtech.in). Because both regions are active simultaneously, this is not a one-time cutover — transactions can be routed to either region at any time going forward.

Impact if not configured in time

  • Since traffic is actively load-balanced across both regions, any transaction routed to the region your systems cannot reach will fail immediately, not only during a scheduled cutover.
  • This directly affects the go-live timeline for the BG launch — every day this configuration is delayed pushes back the overall rollout.
  • Announcement of the go-live date to merchants is being held until this guide is confirmed as clear and actionable.

2. What Is Required

Applicability: This configuration is required only if your organization has IP whitelisting enabled on your firewall/network for connections to NTT Data Payment Services. If you do not use IP whitelisting (your systems allow outbound connections without restricting by IP), no action is required on your end — you may skip towards Section 4 for the go-live date.

Merchants currently connect via the domain payment.atomtech.in. Under the active-active architecture, this domain will resolve to and route traffic across the eight IP addresses below (four per site), so if IP whitelisting is enabled at your end, update your network/firewall configuration to whitelist all eight IP addresses — four for Site 1, four for Site 2 — since both sites serve live traffic under the active-active architecture.

payment.atomtech.in

Under the active-active architecture, the domain may route traffic across the following IP addresses.

Whitelist Configuration

RegionIP Address
Existing Domainpayment.atomtech.in
Site 135.154.45.217
Site 113.201.154.107
Site 143.204.105.74
Site 113.127.127.18
Site 240.192.72.6
Site 298.130.32.67
Site 298.130.69.236
Site 216.112.49.135
Port(s)443 (HTTPS)
ProtocolHTTPS / TLS

Note: Please ensure all eight IP addresses listed above are added to your whitelist, regardless of whether any may already be present.

Steps for Merchants

  1. Identify the firewall/proxy that controls outbound connectivity from your payment integration.
  2. Add all eight IP addresses above to your allowlist, on port 443 (HTTPS/TLS).
  3. Keep all eight IP addresses reachable at all times — since both regions are active simultaneously, none of them are backup-only.
  4. Run the network test in Section 3 to confirm connectivity to each of the eight IP addresses.

3. How to Confirm (Network Test)

Once your firewall/network configuration is updated, confirm connectivity to all eight IP addresses (Site 1 and Site 2) using a telnet test on port 443, run from the same server(s) that connect to the payment platform.

Test Commands

telnet 35.154.45.217 443
telnet 13.201.154.107 443
telnet 43.204.105.74 443
telnet 13.127.127.18 443
telnet 40.192.72.6 443
telnet 98.130.32.67 443
telnet 98.130.69.236 443
telnet 16.112.49.135 443

Expected Result

Each command should establish a connection successfully, such as:

Connected to <IP>

or show a blank connected session without an immediate timeout or connection refusal.

All eight tests must succeed.

If the Test Fails (connection refused / timed out)

  • Confirm the IP address and port (443) were entered exactly as provided in the Section 2 table.
  • Confirm your firewall/proxy rule allowing outbound access to that IP on port 443 has been applied and is not blocked by an upstream device.
  • If the issue persists, contact support using the details in Section 6, including your merchant ID and the telnet output.

4. When — Timeline

MilestoneTarget DateOwner
Merchant configuration guide issuedSeptember 8, 2026NTT Data Payment Services
Merchant network configuration window opensSeptember 9, 2026Merchant
Merchant network test / connectivity confirmation dueSeptember 15, 2026Merchant
Blue-Green (BG) cutover / go-liveSeptember 20, 2026NTT Data Payment Services

Note: The merchant network test / connectivity confirmation deadline allows a buffer before go-live to resolve any failed tests. Merchants who cannot complete configuration by this date should contact support immediately.


5. FAQ and In Case of Query

  1. Does this apply to me if I don't use IP whitelisting?

No. This configuration change is only required if your organization has IP whitelisting enabled on your firewall/network for connections to NTT Data Payment Services. If your systems do not restrict outbound connections by IP address, no action is required on your end.

  1. Why is this change required?

NTT Data Payment Services is introducing a Blue-Green (BG) active-active architecture to maximize system availability. Both regions — including a new Site 2-based region — serve live traffic at the same time, and transactions are dynamically routed between them to balance load. This requires merchants to whitelist a secondary connection path (four secondary IP addresses routed via the Site 2-based region) alongside the existing primary connection (payment.atomtech.in).

  1. What happens if I don't configure this before the deadline?

Because both regions actively share transaction traffic (not just failover), any transaction routed to the region your systems cannot reach will fail immediately, not only during a scheduled cutover. This can result in failed or delayed transactions until your firewall/network configuration is updated.

  1. Do I need to make any changes to my application code?

In most cases, no code changes are required — only a network/firewall configuration change to allow outbound connectivity to the new domain and/or secondary IP listed in this guide. Please confirm with your own technical team based on how your integration is implemented.

  1. How do I know the configuration was successful?

Run a telnet test to each of the eight IP addresses (Site 1 and Site 2) on port 443, as described in the "How to Confirm" section, and confirm all eight connections succeed. If any test fails, see the troubleshooting steps in that section or contact support.

  1. Who do I contact if I have questions or the test fails?

Please contact the PG Helpdesk at 1860 266 4959 (option 1). Include your merchant ID and the output of your network test.

  1. Is there a cost or downtime associated with this change?

No, there is no cost or downtime involved. The change is a one-time network configuration update on the merchant side.


6. Support Contact

For any questions regarding this guide or network configuration:

  • Team: PG Helpdesk
  • Telephone: 1860 266 4959 (Option 1)
  • Email: NDPS.helpdesk@nttdata.com
  • Support Hours: 8:00 AM to 8:00 PM, Monday to Saturday (Closed on Sundays)