Introduction
When managing tens or hundreds of ESXi hosts, consistent configuration becomes critical. From network setup to service policies and firmware compliance, PowerCLI enables administrators to inspect, update, and enforce standards across all nodes.
This article will walk through:
- Networking and switch configuration
- Setting host DNS, NTP, and advanced options
- Managing host services and lockdown mode
- Patch-level discovery and host profile validation
- Generating compliance reports
My Personal Repository on GitHub
Network Configuration and vSwitch Management
View All Host Networking Details
Get-VMHostNetworkAdapter -VMHost esxi01.lab.local
Get-VirtualSwitch -VMHost esxi01.lab.local
Add a New vSwitch and Port Group
# Create vSwitch2
New-VirtualSwitch -VMHost esxi01.lab.local -Name "vSwitch2" -Nic vmnic1
# Create port group on new switch
New-VirtualPortGroup -VirtualSwitch "vSwitch2" -Name "Backup_Network"
Assign VMkernel NIC for vMotion
New-VMHostNetworkAdapter -VMHost esxi01.lab.local -PortGroup "vMotion" `
-IP "192.168.50.11" -SubnetMask "255.255.255.0" -VMKernel
Host DNS, NTP, and Advanced Settings
Set DNS and Domain Suffixes
Get-VMHost | Set-VMHostNetwork -DomainName "lab.local" -DnsAddress "192.168.1.1","192.168.1.2"
Configure NTP Settings on All Hosts
$ntpServers = "0.pool.ntp.org","1.pool.ntp.org"
Get-VMHost | ForEach-Object {
Add-VMHostNtpServer -VMHost $_ -NtpServer $ntpServers
Start-VMHostService -HostService ($_ | Get-VMHostService | Where-Object {$_.Key -eq "ntpd"})
Set-VMHostService -HostService ($_ | Get-VMHostService | Where-Object {$_.Key -eq "ntpd"}) -Policy "on"
}
Managing Host Services and Security Modes
Enable or Disable SSH on All Hosts
Get-VMHost | Get-VMHostService | Where-Object {$_.Key -eq "TSM-SSH"} | Set-VMHostService -Policy "off" -Confirm:$false
Toggle Lockdown Mode
Set-VMHost -VMHost esxi01.lab.local -LockdownEnabled $true
Lockdown mode restricts remote access. Use it in environments with centralized authentication only.
Validate Patch Levels and Build Consistency
List ESXi version and build numbers:
Get-VMHost | Select Name, Version, Build
Compare against baseline build to validate compliance.
Diagram: Host Compliance Workflow

Generate Host Configuration Report
Export key values across all hosts:
Get-VMHost | Select Name, State, Version, Build, ConnectionState, Manufacturer, Model, @{N="vSwitchCount";E={($_ | Get-VirtualSwitch).Count}} | Export-Csv "C:\Reports\Host_Config.csv" -NoTypeInformation
Use Case: Post-Deployment Host Hardening
Many security baselines require post-installation steps such as:
- Disabling unused services
- Enforcing NTP
- Enabling lockdown and firewall policies
PowerCLI can apply these settings to every host in a single pass, ensuring rapid compliance.
Get-VMHost | Set-VMHost -LockdownEnabled $true
Get-VMHost | Get-VMHostService | Where-Object {$_.Key -eq "DCUI"} | Set-VMHostService -Policy "off"
Troubleshooting and Best Practices
| Issue | Fix |
|---|---|
Set-VMHostNetwork fails | Validate permissions and whether DNS is managed by host profile |
| SSH service refuses to start | Ensure host firewall allows SSH access |
| NTP status shows offline | Check upstream firewall and NTP hostname resolution |
| Services revert after reboot | Ensure Policy is set to on or off to persist state |
What’s Next
The next article will dive into vCenter Object Management, including:
- Automating roles and permissions
- Managing alarms and tasks
- User and group inspection across SSO