To reconfigure your SDDC for compliance with PCI, you must download and license additional VMware and third-party software.

VMware Validated Design Security and Compliance Configuration for PCI uses scripts and commands based on VMware PowerCLI to reconfigure the SDDC. You must prepare a host with supported OS for running Microsoft PowerShell, set-up Microsoft PowerShell, and install the latest version of VMware PowerCLI. The host must have connectivity to the ESXi management network in the management cluster.

Table 1. Third-Party Software Required for VMware Validated Design Security and Compliance Configuration for PCI

SDDC Layer

Product Group

Script/Tool

Download Location

Description

Virtual Infrastructure

VMware PowerCLI

Supported OS for VMware PowerCLI

n/a

Operating system that supports Microsoft PowerShell and VMware PowerCLI. For more information on supported operating systems, see VMware PowerCLI User's Guide.

Virtual Infrastructure

VMware NSX® Data Center for vSphere®

FTP server

n/a

Space for NSX Manager backups must be available on an FTP server. The server must support SFTP and FTP. The NSX Manager instances must have connection to the remote FTP server.

Table 2. VMware Scripts and Tools Required for VMware Validated Design Security and Compliance Configuration for PCI

SDDC Layer

Product Group

Script/Tool

Download Location

Description

Virtual Infrastructure and Operations Management

vSphere, VMware Site Recovery Manager, vRealize Operations Manager

VMware PowerCLI

n/a

VMware PowerCLI contains modules of cmdlets based on Microsoft PowerShell for automating vSphere, VMware Site Recovery Manager, vSphere Automation SDK, vSphere Update Manager, vRealize Operations Manager, NSX-T, and so on. VMware PowerCLI provides a PowerShell interface to the VMware product APIs.