Saturday, 5 September 2026

What's New in vCenter 9.1? Security, Faster Upgrades, and Reduced Operational Complexity

 

With VMware Cloud Foundation (VCF) 9.1, vCenter receives several important enhancements focused on security, operational efficiency, lifecycle management, and upgrade simplification. While many organizations naturally focus on the ESX enhancements in a new release, the improvements in vCenter 9.1 deliver significant value for virtualization administrators responsible for managing and securing their environments.

From built-in file integrity monitoring and streamlined logging to significantly reduced downtime during upgrades, vCenter 9.1 introduces features designed to make day-to-day operations easier and more secure.

Let's explore what's new.


Strengthening Security with File Integrity Monitoring

Security remains a top priority for infrastructure teams, and vCenter 9.1 introduces a powerful new capability: File Integrity Monitoring (FIM).

Aligned with NIST SP 800-115 guidance, FIM continuously monitors critical static files and binaries installed on vCenter for unexpected changes. These modifications could be the result of:

  • Malware activity
  • Unauthorized administrator actions
  • Accidental file corruption
  • Configuration drift

FIM is enabled by default and automatically performs scans every four hours, helping administrators quickly identify potential security incidents or operational issues before they become larger problems.

Key Benefits

  • Continuous monitoring of critical vCenter components
  • Early detection of unauthorized changes
  • Improved security and compliance visibility
  • Built-in auditing capabilities

Administrators can retrieve FIM reports through APIs or stream monitoring data directly into VCF Operations through the syslog service, enabling centralized visibility across the VMware estate.

As cyber threats continue to target management infrastructure, FIM adds an important additional layer of protection for vCenter environments.


Built-In Log Management Agent

Log management is often one of the first challenges administrators face when deploying monitoring and observability solutions.

To simplify this process, vCenter 9.1 now includes a pre-installed Logs Management Agent.

This agent:

  • Automatically forwards logs to VCF Operations
  • Persists through upgrades
  • Reduces manual deployment steps
  • Simplifies centralized log collection

Previously, organizations frequently needed to deploy and maintain logging agents as a separate operational task. By embedding the capability directly into vCenter, VMware streamlines observability and reduces administrative overhead.

For operations teams focused on troubleshooting, auditing, and compliance reporting, this enhancement provides immediate value.


Modernizing the vCenter Appliance with VM Hardware Version 17

Another notable update in vCenter 9.1 is the upgrade of the vCenter appliance virtual machine hardware version.

From vmx-10 to vmx-17

The vCenter Server Appliance now runs on VM hardware version 17, representing a substantial jump from the previous vmx-10 baseline.

Benefits include:

  • Better alignment with modern ESX capabilities
  • Enhanced virtual hardware support
  • Improved compatibility with current infrastructure platforms
  • Access to newer virtualization technologies

For customers upgrading from VCF 9.0, VMware provides guidance for manually updating the vCenter VM hardware version to take advantage of the latest platform capabilities.

While this may not be the most visible enhancement, it helps ensure the management plane remains aligned with the underlying virtualization platform.


Proactive Upgrade Readiness with On-Demand RDU Pre-Checks

One of the biggest causes of upgrade delays is discovering environmental issues too late in the process.

To address this challenge, vCenter 9.1 introduces on-demand pre-checks for Reduced Downtime Upgrades (RDU).

These checks operate similarly to traditional vCenter patching pre-checks and allow administrators to validate upgrade readiness before beginning the upgrade process.

Advantages Include

  • Early identification of upgrade blockers
  • Reduced risk during maintenance windows
  • Faster upgrade troubleshooting
  • Improved planning and scheduling

Instead of waiting for issues to surface during an upgrade, teams can proactively verify the environment and resolve problems ahead of time.

This enhancement is particularly valuable for organizations operating large-scale production environments where maintenance windows are limited.


Simplified Reduced Downtime Upgrades

VMware continues to improve lifecycle management with enhancements to the Reduced Downtime Upgrade (RDU) process.

Historically, administrators needed to:

  1. Download an ISO image
  2. Transfer the image
  3. Mount the ISO
  4. Begin the upgrade workflow

With vCenter 9.1, much of that complexity disappears.

Automated Payload Downloads

The RDU workflow can now automatically download required upgrade payloads directly from the Broadcom online repository.

This simplifies the upgrade process by:

  • Eliminating manual ISO handling
  • Reducing administrative effort
  • Streamlining patch preparation
  • Improving operational efficiency

For organizations managing multiple vCenter instances, the time savings can become substantial over the course of a year.


vCenter Quick Patch: Security Fixes with Minimal Downtime

Perhaps the most exciting operational feature in vCenter 9.1 is the introduction of vCenter Quick Patch.

Traditionally, even minor security updates often required maintenance windows and service interruptions.

Quick Patch changes that experience dramatically.

What is Quick Patch?

Quick Patch enables administrators to install:

  • Security fixes
  • Critical bug fixes

with downtime measured in minutes rather than hours.

Importantly, Quick Patch is designed for patching and maintenance activities and is not intended for major version upgrades.


Downtime Categories

vCenter Quick Patch intelligently evaluates the services affected by the patch and places updates into one of three categories:

Zero Downtime

No service interruption required.

Zero to Three Minutes

Minimal disruption for lightweight service updates.

Three to Five Minutes

Short maintenance window for more substantial service updates.

This allows organizations to maintain a stronger security posture by applying critical updates more frequently without waiting for large maintenance windows.


Why These Features Matter

Taken together, the vCenter 9.1 enhancements focus on three key operational goals:

Better Security

  • File Integrity Monitoring
  • Built-in logging integration
  • Faster patch deployment
  • Improved visibility into platform changes

Simplified Operations

  • Pre-installed log management agent
  • Automated RDU payload downloads
  • On-demand upgrade readiness checks

Reduced Downtime

  • Reduced Downtime Upgrade improvements
  • Quick Patch functionality
  • Faster maintenance workflows

These enhancements help administrators spend less time managing infrastructure and more time delivering value to the business.


Final Thoughts

vCenter 9.1 may not introduce flashy new management interfaces or dramatic architectural changes, but it delivers meaningful improvements where infrastructure teams need them most: security, observability, lifecycle management, and availability.

The introduction of File Integrity Monitoring strengthens the security posture of the management plane, while automated upgrade preparation and payload downloads make lifecycle operations considerably easier. The standout feature, however, is undoubtedly vCenter Quick Patch, which enables organizations to apply critical updates with as little as zero to five minutes of downtime.

For VMware administrators running VMware Cloud Foundation, these enhancements represent another step toward a more secure, resilient, and operationally efficient private cloud platform. As organizations continue to modernize infrastructure and support increasingly critical workloads, vCenter 9.1 provides the tools necessary to keep management services secure, current, and highly available.

Friday, 4 September 2026

ESX 9.1 in VMware Cloud Foundation: A Major Leap Forward for Automation, Security, AI, and Performance

 

VMware Cloud Foundation (VCF) 9.1 introduces one of the most significant updates to ESX in recent years, delivering major enhancements across installation, storage, security, virtualization, AI infrastructure, memory management, and operational efficiency. Whether you're managing traditional enterprise workloads, modern Kubernetes platforms, or AI and HPC environments, ESX 9.1 provides new capabilities designed to simplify operations while improving performance, resiliency, and security.

Let's take a closer look at the key innovations introduced in ESX 9.1.


Simplified Host Deployment with Zero Touch Provisioning

One of the standout features in VCF 9.1 is Zero Touch Provisioning (ZTP), a modernized approach to ESX deployment.

Traditionally, provisioning ESX hosts at scale required PXE boot infrastructure, TFTP servers, and significant network configuration. ZTP eliminates these dependencies by leveraging secure UEFI boot and HTTPS-based image delivery.

Benefits include:

  • No PXE infrastructure requirements
  • No TFTP configuration
  • Faster and more secure installations
  • Ability to provision multiple hosts from a single HTTPS endpoint
  • Simplified deployment for bare-metal environments

ZTP effectively replaces the legacy Auto Deploy model, which was deprecated in VCF 9.0, making large-scale ESX deployments significantly easier to manage.


Enhanced RDMA Visibility and Troubleshooting

As organizations continue adopting high-performance networking technologies such as vSAN over RDMA and NVMe over RDMA, observability becomes increasingly important.

ESX 9.1 introduces new tools to improve RDMA troubleshooting and validation:

RDMA Sniffer

The new command:

pktcap-uw --capture RDMASniffer
``

allows administrators to perform native packet captures for RDMA traffic directly from the hypervisor.

RDMA Performance Validation

The built-in:

rdmaperf-uw

utility enables administrators to:

  • Validate network readiness
  • Verify end-to-end connectivity
  • Measure throughput
  • Analyze latency
  • Troubleshoot RoCEv2 environments

These additions provide much-needed visibility into high-performance network deployments without relying on external tools.


Guest Customization APIs Become More Flexible

Automation continues to be a major focus area, and ESX 9.1 enhances Guest Customization APIs with several highly requested capabilities.

Improved Powered-Off VM Customization

IPv6-Only Networking

Administrators can now explicitly disable IPv4 and deploy VMs using IPv6-only configurations through both the UI and API.

This simplifies modern networking deployments and removes the need for placeholder IPv4 settings.

Partial Network Customization

Previously, modifying network settings often required submitting a complete customization profile.

Now, administrators can update only the network-related parameters, reducing complexity and making automation workflows more efficient.

Expanded Credential Management

New functionality includes:

  • Setting Linux root passwords during deployment
  • Resetting Linux root passwords on existing VMs
  • Resetting Windows Administrator passwords
  • Enhanced Windows guest script execution

These additions provide greater operational flexibility while improving day-two management.

Live Network Changes for Powered-On VMs

Perhaps one of the most impactful enhancements is live network customization.

Network settings can now be modified on running virtual machines without requiring a shutdown, helping administrators reduce downtime and improve operational agility.


Modernized ESX Host Client

The ESX Host Client receives a refreshed experience aligned more closely with the vSphere Client.

The updated interface improves management of:

  • Compute resources
  • Storage configuration
  • Networking operations

Importantly, VMware has maintained full feature parity while delivering a more modern and consistent management experience.


Faster, Smoother Snapshot Operations

Snapshot operations have long presented challenges for VMs with large virtual disks.

ESX 9.1 introduces a significant enhancement to Change Block Tracking (CBT) enablement.

While overall snapshot creation time remains unchanged, VMware has eliminated the VM unresponsiveness that could previously occur during CBT initialization on large disks.

For production workloads, this translates directly into improved user experience and reduced operational impact during backup and snapshot activities.


Linked Clones for First Class Disks

Storage efficiency and rapid provisioning receive a boost with support for linked clones of First Class Disks (FCDs).

This capability enables:

  • Faster storage consumption
  • Improved efficiency for container platforms
  • Rapid provisioning of persistent volumes
  • Better VMware Kubernetes Service (VKS) integrations

Organizations running cloud-native workloads can particularly benefit from faster and more scalable storage operations.


Expanding AI and HPC Infrastructure Support

AI infrastructure continues to drive hardware innovation, and ESX 9.1 significantly expands support for modern accelerators.

NVIDIA ConnectX-7 and BlueField-3

Enhanced DirectPath now supports:

  • NVIDIA Mellanox ConnectX-7
  • NVIDIA BlueField-3

This enables high-performance passthrough architectures while preserving virtualization benefits such as:

  • vMotion
  • Storage vMotion
  • Live Patch
  • Hot-add and hot-remove operations

AMD MI350 GPU Support

ESX 9.1 also introduces support for the AMD MI350 accelerator platform.

The result is:

  • Faster AI training
  • Improved inference performance
  • Continued virtualization flexibility
  • Better operational management of AI infrastructure

Organizations investing in AI workloads can take advantage of near-native performance without sacrificing manageability.


New Hardware Platform Support

VMware continues to expand hardware compatibility with support for the Intel E825 network controller, integrated into Intel Xeon Generation 6 (Granite Rapids-D) systems.

This ensures organizations can confidently deploy next-generation server platforms while maintaining ESX compatibility.


IOMMU Virtualization for AMD DirectPath Workloads

ESX 9.1 introduces IOMMU virtualization for AMD hosts using DirectPath devices.

This enhancement delivers:

  • Near-native device performance
  • Improved memory isolation
  • Enhanced security
  • Better workload efficiency

For performance-sensitive workloads, this represents an important advancement in passthrough device support.


Significant Security Advancements

Security is one of the strongest themes throughout the ESX 9.1 release.

Quick Boot for Confidential VM Environments

Administrators running confidential workloads can now take advantage of Quick Boot.

Rather than requiring:

  • Full hardware reboot
  • Firmware initialization
  • Lengthy maintenance operations

Quick Boot allows hosts to restart significantly faster, reducing upgrade and maintenance windows.


User-Level Monitor (ULM)

Perhaps the most transformative security enhancement is the introduction of User-Level Monitor (ULM) as the default monitor for all virtual machines.

ULM fundamentally rearchitects how virtual machines are executed by:

  • Moving significant functionality out of privileged kernel space
  • Reducing hypervisor attack surface
  • Limiting opportunities for guest-to-host compromise
  • Improving overall platform security

This represents a major evolution in ESX virtualization architecture.


AMD SEV-SNP Reaches General Availability

After a limited availability period in ESX 9.0, AMD Secure Encrypted Virtualization Secure Nested Paging (SEV-SNP) is now generally available.

Key capabilities include:

  • Hardware-based Trusted Execution Environment (TEE)
  • Memory encryption
  • Memory integrity verification
  • Replay attack protection
  • Memory remapping protection
  • Remote attestation

Supported on AMD EPYC Milan (Zen 3) and newer processors, SEV-SNP delivers stronger protection for highly sensitive workloads.


Intel TDX Now Generally Available

Intel Trusted Domain Extensions (TDX) also achieves general availability in ESX 9.1.

TDX provides:

  • Confidential computing capabilities
  • Hardware-backed attestation
  • Isolation from host-level threats
  • Data confidentiality protection

Support begins with Intel Xeon Gen 5 (Emerald Rapids) processors and newer platforms.

Together, SEV-SNP and TDX establish ESX 9.1 as a leading platform for confidential computing.


Improved Logging Performance

System observability continues to improve through enhancements to vmsyslogd.

The service now handles greater logging volumes across:

  • TCP
  • SSL
  • UDP

For environments generating large quantities of log data, this translates into improved reliability, performance, and operational visibility.


Memory Tiering Becomes Easier and More Resilient

Memory Tiering receives some of the most practical operational improvements in ESX 9.1.

No Reboot Required

Administrators can now:

  • Enable Memory Tiering
  • Configure Memory Tiering
  • Select tiering devices

without requiring a host reboot.

This dramatically reduces deployment time and maintenance costs.

Support for All VM Types

Previous restrictions have been removed, allowing Memory Tiering to support:

  • Low-latency workloads
  • Security-focused workloads
  • Large memory-intensive "monster" VMs

RAID1 Protection for Tiered Memory

Perhaps most importantly, ESX 9.1 introduces software RAID1 mirroring for Memory Tiering devices.

Benefits include:

  • Increased resiliency
  • Protection against NVMe failures
  • Continuous operations during device outages
  • No performance degradation

With mirrored NVMe devices, memory tiering remains available even when a primary device fails.


Final Thoughts

ESX 9.1 represents far more than a routine platform update. VMware has focused on the areas most important to modern infrastructure teams: automated deployment, AI readiness, confidential computing, security hardening, operational efficiency, and infrastructure resiliency.

From Zero Touch Provisioning and live guest customization to User-Level Monitor, confidential computing technologies, RDMA observability, and enhanced memory tiering, ESX 9.1 delivers meaningful improvements for both cloud-scale operators and enterprise data centers.

For organizations planning their next VMware Cloud Foundation upgrade, ESX 9.1 offers compelling reasons to move forward, providing a more secure, flexible, and future-ready platform for today's workloads and tomorrow's innovations.

Thursday, 3 September 2026

Guest Operating System Support in VCF and vSphere 9.1: What's New and What's Changing

 

As organizations continue modernizing their infrastructure with VMware Cloud Foundation (VCF) and vSphere, keeping track of guest operating system support is essential for maintaining compatibility, security, and operational efficiency. With the release of VCF 9.1 and ESX 9.1, VMware introduces support for several new operating systems while retiring support for a number of legacy platforms.

In this article, we'll explore the latest guest OS support updates, highlight deprecated and terminated operating systems, and examine a new VMware Tools enhancement designed to simplify virtual machine lifecycle management.

Guest Operating System Compatibility in ESX 9.1

Before deploying or upgrading workloads, administrators should always verify operating system compatibility against the official Broadcom Compatibility Guide. This remains the authoritative source for validating supported guest operating systems on ESX 9.1.

The latest release expands support for several modern operating systems, ensuring customers can take advantage of current platform innovations while maintaining VMware's enterprise-grade virtualization capabilities.

Newly Supported Guest Operating Systems

ESX 9.1 introduces support for the following major operating system releases:

Ubuntu 26.04 LTS

Canonical's latest Long Term Support release joins the supported guest OS list, providing organizations with a stable Linux platform backed by extended support and security updates.

SUSE Linux Enterprise Server 16

SUSE customers can now deploy and virtualize workloads on the latest version of SUSE Linux Enterprise Server, enabling access to new features and performance improvements.

Debian 13.0

Debian remains a staple operating system in many enterprise and development environments. The addition of Debian 13.0 ensures continued support for organizations leveraging this highly reliable Linux distribution.

FreeBSD 15.0

For environments running FreeBSD workloads, ESX 9.1 now supports FreeBSD 15.0, helping organizations modernize while maintaining compatibility with VMware infrastructure.

Pardus 25.0

Pardus, the Linux distribution widely adopted within various public sector and enterprise environments, is now officially supported in ESX 9.1.

CentOS Stream 10 (Technology Preview)

CentOS Stream 10 support is available as a Technology Preview, allowing customers to evaluate and test workloads running on this platform. As with all preview features, administrators should carefully assess suitability before using it in production environments.

VMware Cloud Foundation 9.1 Additions

In addition to the ESX 9.1 guest operating system updates, VCF 9.1 introduces:

CentOS Stream 9 (Technology Preview)

Organizations still operating on CentOS Stream 9 can continue their testing and validation efforts under VCF 9.1 through Technology Preview support.

This provides a bridge for customers evaluating migration paths while maintaining access to newer CentOS Stream releases.

Operating Systems Reaching End of Support

While new operating systems are being introduced, VMware is also removing support for several aging platforms. This is an important consideration for organizations planning upgrades to ESX 9.1 or VCF 9.1.

Terminated Support

The following guest operating systems are no longer supported:

  • Red Hat Enterprise Linux (RHEL) 4.x
  • Oracle Linux 5.x
  • CentOS 4.x
  • CentOS 5.x
  • SUSE Linux Enterprise Server 10 SP4
  • SUSE Linux Enterprise Desktop 12
  • Debian 7.x
  • Flatcar Container Linux 3033 LTS
  • Asianux 3.x

Organizations still running workloads on these platforms should prioritize migration strategies to supported operating system versions to maintain vendor support and reduce security risks.

Deprecated Support

The following operating system remains supported for now but is marked for future removal:

  • Asianux 4.x

Deprecation serves as an early warning for administrators to begin planning migration efforts before support is completely withdrawn in future releases.

Improved Visibility for Windows VM Reboots

One of the most practical enhancements in VCF 9.1 comes through VMware Tools 13.1.0.

Windows Guest OS Pending Reboot Reporting

After upgrading VMware Tools within a Windows virtual machine, administrators have traditionally needed to track reboot requirements manually or rely on in-guest monitoring. VMware Tools 13.1.0 addresses this challenge by introducing a new pending reboot status indicator.

The feature provides:

  • A visual reboot status within the vCenter user interface.
  • API access to reboot status information.
  • Improved visibility of virtual machines requiring a restart after VMware Tools upgrades.
  • Better scheduling and planning of maintenance windows.
  • Reduced operational overhead for large-scale environments.

For organizations managing hundreds or thousands of Windows virtual machines, this enhancement can significantly streamline upgrade operations and improve overall maintenance efficiency.

Why These Changes Matter

The guest operating system updates in VCF and vSphere 9.1 reflect a broader industry trend: supporting modern, secure operating systems while retiring legacy platforms that no longer meet enterprise requirements.

Key benefits include:

  • Access to the latest Linux and FreeBSD releases.
  • Improved compatibility for modern application workloads.
  • Enhanced security through the retirement of end-of-life operating systems.
  • Better operational visibility with VMware Tools reboot reporting.
  • Simplified lifecycle management across virtualized environments.

Final Thoughts

VCF 9.1 and ESX 9.1 continue VMware's focus on delivering a modern virtualization platform that supports current operating system releases while helping organizations phase out legacy environments.

The addition of operating systems such as Ubuntu 26.04 LTS, Debian 13.0, SUSE Linux Enterprise Server 16, and FreeBSD 15.0 demonstrates VMware's commitment to enabling modern workloads across diverse environments. At the same time, the retirement of older platforms serves as a reminder that infrastructure modernization is an ongoing process.

Combined with the new Windows Guest OS Pending Reboot Reporting capability in VMware Tools 13.1.0, VCF 9.1 provides administrators with better visibility, improved lifecycle management, and enhanced operational efficiency for today's virtualized data centers.

For customers planning upgrades to VCF 9.1 or ESX 9.1, now is the ideal time to review guest operating system inventories, validate compatibility, and develop migration plans for any workloads still dependent on deprecated or unsupported operating systems.

Thursday, 27 August 2026

Resolving the "vSAN Host Cannot Be Moved to the Destination Cluster" Error

When building or expanding VMware Cloud Foundation (VCF) environments, administrators may occasionally encounter the error: "The vSAN host cannot be moved to the destination cluster." 

This message can be caused by residual vSAN metadata that still exists on the host. 

Understanding the Root Cause 

Even after a host has been removed from a vSAN cluster, re-imaged, or repurposed for a new VCF workload domain, it may retain information from its previous vSAN membership. This hidden state can prevent the host from joining a new vSAN-enabled cluster. 

Common remnants include previous vSAN cluster membership information, vSAN cluster UUID associations, disk group metadata, and orphaned or empty vSAN datastores. 

How to Verify Existing vSAN Membership 

Connect to the ESXi host via SSH and run: 

                esxcli vsan cluster get 

This command displays the current vSAN cluster details known to the host, including cluster membership and UUID information. 

Removing the Stale vSAN Association 

If the host is still associated with a previous cluster, run: 

                esxcli vsan cluster leave 

This removes the host's vSAN cluster membership and clears the associated configuration. 

Afterwards, verify the status again using: 

                esxcli vsan cluster get 

Adding the Host to the New Cluster 

Once the stale vSAN state has been removed, return to vCenter Server and retry adding the host to the destination cluster. In most cases, the process will complete successfully. 

Best Practices 

Properly remove hosts from vSAN clusters before decommissioning. 
• Verify vSAN membership has been cleared before repurposing hardware. 
• Check for residual vSAN datastores after re-imaging hosts. 
• Include vSAN state validation in VCF host commissioning procedures. 

Conclusion 

The error typically results from leftover vSAN metadata rather than an issue with the destination cluster. Using esxcli vsan cluster get and esxcli vsan cluster leave allows administrators to quickly identify and remove stale cluster associations so hosts can be successfully added to their new vSAN environments.