Emergency server help: get in touch

Enable SSH on ESXi and the 40 esxcli commands every VMware admin needs

Turn on SSH for ESXi 7, 8 and 9 from the client, DCUI or PowerCLI, lock it down, and keep a working set of esxcli commands for host, network, storage, VM, software and hardware checks that cover daily operations.

Published Updated 5 min read

The vSphere Client covers most daily work, but there is a class of problems (hung VMs, stuck tasks, storage paths, driver versions) that is faster and clearer from the host shell. esxcli is the structured command line for ESXi; its namespaces mirror the host’s subsystems and its output is consistent across ESXi 7.0, 8.0 U3 and 9.x. This guide first covers enabling SSH properly, then lists the commands we reach for most, grouped by task.

Short answer: Enable SSH temporarily from the vSphere Client under host » Configure » Services » SSH » Start (or in the DCUI under Troubleshooting Options), keep the service policy at “Start and stop manually” so it does not survive a reboot, and restrict it with the ESXi firewall to your management subnet. Then use esxcli namespaces such as esxcli system, esxcli network, esxcli storage, esxcli vm and esxcli software to inspect and change the host; esxcli --help at any level lists what is available.

Enable SSH the safe way

In the vSphere Client: select the host » Configure » System » Services » SSH » Start. Leave the startup policy at manual. From PowerCLI across a cluster:

Get-VMHost | Get-VMHostService | Where-Object Key -eq "TSM-SSH" | Start-VMHostService
Get-VMHost | Get-VMHostService | Where-Object Key -eq "TSM-SSH" | Stop-VMHostService -Confirm:$false

From the DCUI: F2 » Troubleshooting Options » Enable SSH. Restrict the source with the firewall once connected:

esxcli network firewall ruleset set -r sshServer -a false
esxcli network firewall ruleset allowedip add -r sshServer -i 10.10.0.0/24
esxcli network firewall ruleset list -r sshServer

Set an idle timeout so forgotten sessions close: Advanced System Settings » UserVars.ESXiShellInteractiveTimeOut (seconds) and UserVars.ESXiShellTimeOut, or via esxcli system settings advanced set -o /UserVars/ESXiShellInteractiveTimeOut -i 900. The warning “SSH for the host has been enabled” in the client is by design; suppress it only on lab hosts.

Host and system

esxcli system version get
esxcli system hostname get
esxcli system maintenanceMode get
esxcli system maintenanceMode set --enable true
esxcli system settings advanced list -o /Misc/APDTimeout
esxcli system ntp get
esxcli system syslog config get
esxcli system boot device get
esxcli system account list
esxcli system stats uptime get

Use esxcli system shutdown reboot -r "patching" for a scripted reboot; it requires maintenance mode.

Networking

esxcli network nic list
esxcli network nic get -n vmnic0
esxcli network ip interface list
esxcli network ip interface ipv4 get
esxcli network ip route ipv4 list
esxcli network ip dns server list
esxcli network vswitch standard list
esxcli network vswitch dvs vmware list
esxcli network firewall get
esxcli network ip connection list

esxcli network nic get shows link state, speed and driver; ip connection list is the netstat equivalent when you need to see what a host is talking to.

Storage

esxcli storage core adapter list
esxcli storage core adapter rescan --all
esxcli storage core device list
esxcli storage core path list
esxcli storage nmp device list
esxcli storage filesystem list
esxcli storage vmfs extent list
esxcli storage nfs list
esxcli iscsi adapter list
esxcli iscsi session list

Path and device lists are the first stop for the APD and PDL states described in Fix ESXi “Datastore not accessible”. esxcli storage core device stats get gives per-device error counters when latency is in question.

For virtual machines:

esxcli vm process list
esxcli vm process kill --type=soft --world-id=<id>

esxcli’s VM namespace is deliberately small; pair it with vim-cmd vmsvc/getallvms, vim-cmd vmsvc/power.getstate <id> and vim-cmd vmsvc/get.tasklist <id> for inventory and task work, as covered in Kill an unresponsive VM on ESXi.

Software and hardware

esxcli software profile get
esxcli software vib list
esxcli software vib get -n nvme-pcie
esxcli software sources profile list -d /vmfs/volumes/ds1/depot.zip
esxcli software profile update -d /vmfs/volumes/ds1/depot.zip -p <profile>
esxcli hardware cpu list
esxcli hardware memory get
esxcli hardware platform get
esxcli hardware ipmi sel list

esxcli hardware platform get returns the model and serial number without a trip to the data centre, and ipmi sel list reads the hardware event log for failed DIMMs and PSU events.

Every esxcli command accepts --formatter for scripting:

esxcli --formatter=csv network nic list
esxcli --formatter=keyvalue storage filesystem list
esxcli --formatter=json system version get

JSON output pairs well with a monitoring agent that shells in over SSH, though the vSphere API is the better long-term choice for anything polled regularly.

Clean up and avoid the common pitfall

After finishing, stop SSH (Stop-VMHostService or the client) and confirm the service is off with esxcli network firewall ruleset list -r sshServer showing the ruleset disabled. Host profiles and Lifecycle Manager can flag hosts with SSH left running, which is a useful compliance check.

Setting the SSH policy to “Start and stop with host” for convenience leaves an interactive root shell exposed on every host permanently. Combined with a shared root password, it undermines every other control. Enable on demand, use lockdown mode with an exception user for automation, and forward the auth log to syslog so logins are visible.

Esxcli commands at a glance

Enable SSH on ESXi and the 40 esxcli commands every VMware a summary card: Enable SSH temporarily from the vSphere Client under host » Configure » Services » SSH » Start (or in the DCUI under…
In short: Enable SSH temporarily from the vSphere Client under host » Configure » Services » SSH » Start (or in the DCUI under Troubleshooting Options), keep the service policy at “Start and stop manually” so it does not survive a reboot, and…

Official documentation: Broadcom TechDocs (VMware), AlmaLinux wiki, Linux man pages.

Related guides: Fix Windows Autopilot enrollment errors 80180003 and 80180014 · What changed in cPanel 138: Meridian, Ask AI, Nova, MCP and domain rename · Upgrade vCenter Server Appliance 8.0 to 9.x with the Migration Assistant.

Frequently asked questions

Does esxcli work the same on ESXi 9 as on 7 and 8?

The namespaces and commands listed here exist on all three, with 9.x adding options rather than removing them. A few storage and network subcommands gained fields in 8.0; esxcli <namespace> --help shows the exact syntax for the build you are on.

How long can SSH stay enabled on an ESXi host?

There is no built-in limit, but the interactive and shell timeouts can close idle sessions and the service can be scheduled off with PowerCLI. Treat any host with SSH running for more than a maintenance window as a finding.

Can I run esxcli remotely without SSH?

Yes. PowerCLI’s Get-EsxCli -V2 exposes the same namespaces through the vSphere API, and the standalone ESXCLI package can target a host over HTTPS with --server. Both avoid an open shell on the host.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.