You perform procedures on the ESXi hosts in all your workload domains by using different interfaces, such as PowerCLI, ESXi Shell, and the vSphere Client.
Procedure
Security Best Practices for Securing ESXi Hosts You must follow multiple best practices at all times when you operate your ESXi hosts.
Configure Multiple Security Settings on the ESXi Hosts by Using the ESXi Shell You activate secure boot on all the ESXi hosts.
Configure Multiple Security Settings on the ESXi Hosts by Using PowerCLI You perform the procedure on all ESXi hosts in all your workload domains to configure firewall settings, password policy, inactivity timeouts, failed login attempts, join ESXi hosts to Active Directory domain, and remove ESX Admin group membership. Also, stop the ESXi shell service, configure login banners for the Direct Console User Interface (DCUI) and SSH connections, deactivate warnings, activate the Bridge Protocol Data Unit (BPDU) filter, configure persistent log location, remote logging, and activate bidirectional CHAP authentication by using PowerCLI commands.
Configure Multiple Security Settings on Unassigned ESXi Hosts by Using PowerCLI You perform this procedure on all unassigned ESXi hosts in the SDDC inventory to configure non-native VLAN ID, Virtual Guest Tagging (VGT), and unreserved VLAN ID on all the port groups on the standard switch.
Activate Normal Lockdown Mode on the ESXi Hosts You activate normal lockdown mode on the ESXi hosts.