Host Configuration and Compliance with PowerCLI: Automating Network, Patch, and Policy Management

Introduction

When managing tens or hundreds of ESXi hosts, consistent configuration becomes critical. From network setup to service policies and firmware compliance, PowerCLI enables administrators to inspect, update, and enforce standards across all nodes.

This article will walk through:

  • Networking and switch configuration
  • Setting host DNS, NTP, and advanced options
  • Managing host services and lockdown mode
  • Patch-level discovery and host profile validation
  • Generating compliance reports

My Personal Repository on GitHub

VMware Repository on GitHub


Network Configuration and vSwitch Management

View All Host Networking Details

Get-VMHostNetworkAdapter -VMHost esxi01.lab.local
Get-VirtualSwitch -VMHost esxi01.lab.local

Add a New vSwitch and Port Group

# Create vSwitch2
New-VirtualSwitch -VMHost esxi01.lab.local -Name "vSwitch2" -Nic vmnic1

# Create port group on new switch
New-VirtualPortGroup -VirtualSwitch "vSwitch2" -Name "Backup_Network"

Assign VMkernel NIC for vMotion

New-VMHostNetworkAdapter -VMHost esxi01.lab.local -PortGroup "vMotion" `
-IP "192.168.50.11" -SubnetMask "255.255.255.0" -VMKernel

Host DNS, NTP, and Advanced Settings

Set DNS and Domain Suffixes

Get-VMHost | Set-VMHostNetwork -DomainName "lab.local" -DnsAddress "192.168.1.1","192.168.1.2"

Configure NTP Settings on All Hosts

$ntpServers = "0.pool.ntp.org","1.pool.ntp.org"

Get-VMHost | ForEach-Object {
Add-VMHostNtpServer -VMHost $_ -NtpServer $ntpServers
Start-VMHostService -HostService ($_ | Get-VMHostService | Where-Object {$_.Key -eq "ntpd"})
Set-VMHostService -HostService ($_ | Get-VMHostService | Where-Object {$_.Key -eq "ntpd"}) -Policy "on"
}

Managing Host Services and Security Modes

Enable or Disable SSH on All Hosts

Get-VMHost | Get-VMHostService | Where-Object {$_.Key -eq "TSM-SSH"} | Set-VMHostService -Policy "off" -Confirm:$false

Toggle Lockdown Mode

Set-VMHost -VMHost esxi01.lab.local -LockdownEnabled $true

Lockdown mode restricts remote access. Use it in environments with centralized authentication only.


Validate Patch Levels and Build Consistency

List ESXi version and build numbers:

Get-VMHost | Select Name, Version, Build

Compare against baseline build to validate compliance.


Diagram: Host Compliance Workflow

Diagram of Host Compliance Workflow.

Generate Host Configuration Report

Export key values across all hosts:

Get-VMHost | Select Name, State, Version, Build, ConnectionState, Manufacturer, Model, @{N="vSwitchCount";E={($_ | Get-VirtualSwitch).Count}} | Export-Csv "C:\Reports\Host_Config.csv" -NoTypeInformation

Use Case: Post-Deployment Host Hardening

Many security baselines require post-installation steps such as:

  • Disabling unused services
  • Enforcing NTP
  • Enabling lockdown and firewall policies

PowerCLI can apply these settings to every host in a single pass, ensuring rapid compliance.

Get-VMHost | Set-VMHost -LockdownEnabled $true
Get-VMHost | Get-VMHostService | Where-Object {$_.Key -eq "DCUI"} | Set-VMHostService -Policy "off"

Troubleshooting and Best Practices

IssueFix
Set-VMHostNetwork failsValidate permissions and whether DNS is managed by host profile
SSH service refuses to startEnsure host firewall allows SSH access
NTP status shows offlineCheck upstream firewall and NTP hostname resolution
Services revert after rebootEnsure Policy is set to on or off to persist state

What’s Next

The next article will dive into vCenter Object Management, including:

  • Automating roles and permissions
  • Managing alarms and tasks
  • User and group inspection across SSO

Continue reading

vCenter Object Management with PowerCLI: Roles, Permissions, Alarms, and Tasks

Explore another guide in this topic and build on what you have just read. Read the article

Leave a Comment

Discover more from Digital Thought Disruption

Subscribe now to keep reading and get access to the full archive.

Continue reading