Panduan Instalasi vSphere untuk Hardware yang Tidak Didukung

Instal VMware ESXi 8.0 pada Dell PowerEdge Generasi Ke-12 (Intel Xeon E5-2600 Series / Sandy Bridge-EP)

Workaround Tidak Resmi untuk Lab Saja

2.0
Version
16 Aug 2026
Updated
6
Server Models
E5-26xx
CPU Family
Hasil Riset & Development HARRY DERTIN SUTISNA — ALSYUNDAWY IT SOLUTION
PERINGATAN KRITIS — Seluruh server Dell PowerEdge generasi ke-12 berbasis Intel Xeon E5-2600 series (Sandy Bridge-EP / CPUID 0x000206D0) seperti R520, R620, R720, R720xd, R820, dan R920 tidak terdaftar dalam official VMware Hardware Compatibility Guide (HCL) atau Dell Compatibility Matrix / Release Certification Matrix (RCM) untuk ESXi 8.x. Pada ESXi 8.0 Update 2, CPU ini berada dalam status Deprecated (peringatan), sedangkan pada ESXi 8.0 Update 3 dan selanjutnya statusnya menjadi Unsupported / Discontinued (diblokir installer). Panduan ini adalah workaround tidak resmi yang hanya ditujukan untuk lab / non-produksi. Tidak ada dukungan vendor, tidak ada jaminan patch keamanan, risiko tinggi driver hilang (PERC, NIC), PSOD, boot failure setelah reboot, dan tidak kompatibel dengan ESXi 9+. Selalu buat full backup dan siapkan rencana rollback. Migrasi ke hardware certified adalah pilihan terbaik.
1

Server yang Berkaitan

Panduan ini berlaku untuk seluruh Dell PowerEdge generasi ke-12 yang menggunakan prosesor Intel Xeon E5-2600 product family (Sandy Bridge-EP). Berikut adalah model-model yang umum digunakan dan spesifikasi intinya:

1.1 Model Server yang Berlaku
ModelForm FactorSocketCPURAM MaksDrive BayPCIeRAID Controller
PowerEdge R5202U Rack2 SocketIntel Xeon E5-2400 series192 GB (12 DIMM)8x 3.5" / 8x 2.5"3-4 PCIe 3.0PERC S110 / H310 / H710 / H710P / H810
PowerEdge R6201U Rack2 SocketIntel Xeon E5-2600 / E5-2600 v2768 GB (24 DIMM)10x 2.5"3 PCIe 3.0PERC S110 / H310 / H710 / H710P / H810
PowerEdge R7202U Rack2 SocketIntel Xeon E5-2600 / E5-2600 v2768 GB (24 DIMM)16x 2.5" / 8x 3.5"7 PCIe 3.0PERC S110 / H310 / H710 / H710P / H810
PowerEdge R720xd2U Rack2 SocketIntel Xeon E5-2600 / E5-2600 v2768 GB (24 DIMM)26x 2.5"6 PCIe 3.0PERC H310 / H710 / H710P / H810
PowerEdge R8202U Rack4 SocketIntel Xeon E5-4600 series768 GB (48 DIMM)16x 2.5"7 PCIe 3.0PERC H310 / H710 / H710P / H810
PowerEdge R9204U Rack4 SocketIntel Xeon E5-4600 / E7 series768 GB (48 DIMM)Storasi ekstensifMultiple PCIe 3.0PERC H710 / H810
1.2 Dell PowerEdge 11G — Tidak Didukung ESXi 8.0 U2+
Dell PowerEdge generasi ke-11 (R510, R610, R710, R810, R910) menggunakan prosesor Intel Xeon 5600/7500 series (Westmere-EP / Nehalem-EX, CPUID 0x000206C1). Server ini tidak bisa menjalankan ESXi 8.0 Update 2 atau yang lebih baru, meskipun allowLegacyCPU=true diberikan.

Alasan: ESXi 8.0 U2 memperkenalkan hard requirement CPU harus mendukung instruksi XSAVE, yang pertama kali hadir pada Intel Sandy Bridge (2011). Westmere-EP (2010) tidak memiliki instruksi ini, sehingga installer akan menolak boot.

Rekomendasi untuk 11G: Gunakan ESXi 6.7 / 7.0, atau pindah ke Proxmox VE 9 yang sepenuhnya kompatibel dengan hardware legacy ini.
1.3 Spesifikasi Kunci Intel Xeon E5-26xx Series
  • Arsitektur: Sandy Bridge-EP (E5-2600 v1) dan Ivy Bridge-EP (E5-2600 v2)
  • Socket: LGA 2011 (v1) / LGA 2011 (v2)
  • Cores: 4, 6, atau 8 cores per processor
  • QPI: 6.4 GT/s, 7.2 GT/s, atau 8.0 GT/s
  • Cache: 2.5 MB per core (15-20 MB L3)
  • Memory: DDR3 1600 MT/s, quad-channel, hingga 768 GB
  • Chipset: Intel C602 / C600
  • CPUID: 0x000206D0 (Sandy Bridge-EP)
1.4 Catatan Penting: Deprecated vs Unsupported
ESXi 8.0 Update 2: Prosesor Intel Xeon E5-2600 series berada dalam status Deprecated. Installer hanya menampilkan peringatan (CPU_SUPPORT_WARNING) dan instalasi/upgrade tetap bisa dilakukan dengan mengabaikan warning.

ESXi 8.0 Update 3 dan selanjutnya: Prosesor ini masuk kategori Unsupported / Discontinued. Installer akan memblokir instalasi dengan error kecuali menggunakan allowLegacyCPU=true. Untuk upgrade dari ESXi 7.x, langkah persiapan tambahan diperlukan agar tidak terhenti di tengah proses.
2

Prasyarat & Persiapan Awal

2.1 Hardware Minimum untuk Workaround
  • CPU: Intel Xeon E5-2600 series (Sandy Bridge-EP) atau E5-2600 v2 (Ivy Bridge-EP) yang mendukung instruksi XSAVE
  • RAM: Minimum 8 GB (sangat disarankan ≥ 16–32 GB untuk produksi lab)
  • Boot device: ≥ 32 GB storage persisten (SSD/HDD lokal; hindari SD/USB sebagai boot utama)
  • Network: Minimal satu adapter Gigabit Ethernet
  • BIOS: Versi terbaru untuk platform tersebut, mode UEFI disukai
2.2 Persiapan Firmware & BIOS
  1. Update komponen berikut ke versi terbaru untuk R720 via Dell Support / Dell Repository Manager:
    • System BIOS, iDRAC, PERC controller (H710 / H710P / H810 / H310), Network adapters, Lifecycle Controller
  2. Pengaturan BIOS yang direkomendasikan:
    • Boot Mode: UEFI
    • Virtualization Technology (VT-x): Enabled
    • VT-d / IOMMU: Enabled
    • Execute Disable Bit (NX/XD): Enabled
    • Secure Boot: Bisa dinonaktifkan sementara jika ada masalah signature
    • Integrated RAID Controller: Enabled
    • Firmware Device Order (FDO) pada PERC: Disabled (tidak didukung oleh ESXi)
2.3 Persiapan Backup
  • Full backup seluruh virtual machine (Veeam, OVF export, atau equivalent)
  • Export konfigurasi host / Host Profile
  • Dokumentasi: management IP, DNS, NTP, pengaturan vSwitch/DVS, nama datastore, license keys, konfigurasi storage
2.4 Download Software
  1. Login ke Broadcom Support Portal.
  2. Navigasi ke VMware vSphere → 8.0 → Custom ISO.
  3. Cari Dell dan download image Dell Customized ESXi 8.0 U3k terbaru jika tersedia.
  4. Jika tidak ada Dell Custom image yang cocok untuk platform lama (umum pada R720), download standard VMware ESXi 8.0 U3k ISO.
  5. Siapkan media bootable: USB (gunakan Rufus mode DD) atau iDRAC Virtual Media
2.5 Pertimbangan vCenter

Jika host dikelola oleh vCenter, upgrade vCenter Server ke versi 8.x sebelum upgrading ESXi hosts (urutan resmi VMware).

3

Prosedur Instalasi Clean

1
Mount Media Instalasi

Siapkan ISO via iDRAC Virtual Media atau boot dari USB yang sudah disiapkan.

2
Boot dari Media

Nyalakan / reboot server dan boot dari installation media.

3
Tambahkan Opsi Kernel

Ketika pesan “Loading ESXi Installer” muncul (dalam ~5 detik), tekan Shift + O.

4
Parameter Boot Kernel

Tambahkan parameter boot kernel berikut:

bash
allowLegacyCPU=true

Contoh baris lengkap:

bash
runweasel cdromBoot allowLegacyCPU=true
5
Konfirmasi

Tekan Enter.

6
Peringatan CPU

Pemeriksaan CPU akan berubah dari Error menjadi Warning. Baca peringatan dengan seksama dan tekan Enter untuk acknowledge.

7
Instalasi Interaktif

Lanjutkan instalasi interactive:

  • Terima EULA (F11)
  • Pilih target disk dengan hati-hati (jangan overwrite data penting)
  • Konfigurasi keyboard layout
  • Set password root yang kuat
  • Konfigurasi management network (static IP direkomendasikan)
8
Reboot

Setelah instalasi selesai, keluarkan media dan reboot host.

3.1 Menyiapkan Media Bootable USB

Gunakan media USB ≥ 8 GB. Pada Linux gunakan dd; pada Windows gunakan Rufus (mode DD Image) atau BalenaEtcher agar struktur ISO ESXi tidak rusak.

Penting: Selalu pilih mode DD Image di Rufus, bukan mode ISO. Mode ISO dapat merusak struktur bootloader ESXi dan menyebabkan instalasi gagal.
3.1.1 Membuat Bootable USB di Linux
Bash
# 1. Identifikasi nama disk USB Anda (HATI-HATI: Jangan salah memilih disk!)
lsblk

# 2. Unmount disk jika ter-mount otomatis
sudo umount /dev/sdX?

# 3. Tulis file ISO ke USB drive (ganti /dev/sdX sesuai disk target USB)
sudo dd bs=4M conv=fdatasync status=progress if=ESXi-8.0u3.iso of=/dev/sdX

# 4. Verifikasi hasil (opsional)
sudo dd if=/dev/sdX bs=4M count=10 | hexdump -C | head -20

# 5. Eject USB dengan aman
sudo eject /dev/sdX
3.1.2 Membuat Bootable USB di Windows — Rufus
LangkahAksiKeterangan
1Unduh RufusDownload dari https://rufus.ie (versi portable OK)
2Pilih DevicePilih USB target ≥ 8 GB (HATI-HATI disk salah, data akan hilang)
3Boot selectionPilih SELECT → pilih file ESXi-8.0u3.iso
4Partition schemeGPT untuk UEFI, atau MBR untuk Legacy BIOS sesuai server Dell
5Image modeJika ditanya, pilih DD Image mode agar bootloader ESXi utuh
6STARTKlik START, tunggu selesai, lalu eject USB dengan aman
3.1.3 Alternatif Windows — BalenaEtcher
Windows — BalenaEtcher
# Langkah-langkah menggunakan BalenaEtcher:
# 1. Unduh BalenaEtcher dari https://www.balena.io/etcher/
# 2. Pilih "Flash from file" → pilih ESXi-8.0u3.iso
# 3. Pilih "Select target" → pilih USB drive target
# 4. Klik "Flash!" dan tunggu hingga selesai
# 5. Eject USB dengan aman
Catatan: Parameter allowLegacyCPU=true primarily diperlukan saat fase installer. Setelah instalasi berhasil, sistem biasanya boot normal tanpa parameter ini. Jika ada masalah post-reboot, lihat section Troubleshooting.
4

Prosedur Upgrade dari ESXi 7.x

4.1 Upgrade Interaktif (Metode ISO)
  1. Letakkan host dalam Maintenance Mode dan evakuasi/shutdown semua VM.
  2. Boot dari ESXi 8.0 ISO (Dell Custom atau standard).
  3. Tekan Shift + O dan tambah allowLegacyCPU=true.
  4. Pilih opsi Upgrade (mempertahankan VMFS datastore dan konfigurasi).
  5. Konfirmasi CPU warning dan selesaikan upgrade.
  6. Reboot host.
Upgrade Note: Untuk ESXi 8.0 Update 2 dan later, jika ISO upgrade gagal karena CPU check, aktifkan allowLegacyCPU secara permanen di host ESXi 7 yang berjalan terlebih dahulu via esxcli system settings kernel set -s allowLegacyCPU -v TRUE atau dengan mengedit /bootbank/boot.cfg, kemudian retry ISO upgrade. Alternatif lain, gunakan CLI method di bawah dengan --no-hardware-warning.
4.2 Metode Upgrade CLI (esxcli)
  1. Letakkan host dalam Maintenance Mode.
  2. Unggah offline depot ZIP (Dell Custom atau standard) ke datastore.
  3. Enable SSH dan jalankan:
bash
esxcli software profile update \
  -d /vmfs/volumes/<datastore-name>/<ESXi-8.0-U3k-bundle>.zip \
  -p <profile-name> \
  --no-hardware-warning
  1. Reboot host:
bash
reboot
4.3 Kickstart / Instalasi Otomatis

Tambahkan opsi berikut ke kickstart file:

text
install --firstdisk --overwritevmfs --ignoreprereqwarnings --ignoreprereqerrors --forceunsupportedinstall

Atau passing allowLegacyCPU=true via boot command line.

5

Skrip Verifikasi Pasca-Instalasi

Simpan script berikut sebagai post_esxi8_unsupported_check.sh dan jalankan setelah host berhasil boot (via SSH atau ESXi Shell).

bash
#!/bin/sh
LOGFILE="/tmp/esxi8_unsupported_verify_$(date +%Y%m%d_%H%M%S).log"
exec > >(tee -a "$LOGFILE") 2>&1

echo "=== Verifikasi Pasca-Instalasi ESXi 8.0 Unsupported Hardware ==="
echo "Tanggal: $(date)"
echo "Nama host: $(hostname)"
echo ""

echo ">>> 1. Versi & Build ESXi"
vmware -v
esxcli system version get
echo ""

echo ">>> 2. CPU & Platform Hardware"
esxcli hardware cpu list | head -25
esxcli hardware platform get
echo ""

echo ">>> 3. Driver & VIB Kritis"
echo "--- Controller Storage (PERC / MegaRAID / Dell) ---"
esxcli software vib list | grep -iE "perc|megaraid|dell|lsi|mpt|sas"
echo ""
echo "--- Driver Network ---"
esxcli software vib list | grep -iE "igb|ixgbe|bnx|tg3|e1000|vmxnet|nmlx|qfle|ixgbe"
echo ""
echo "--- Semua VIB Terkait Dell ---"
esxcli software vib list | grep -i dell
echo ""

echo ">>> 4. Adapter Network Fisik"
esxcli network nic list
echo ""

echo ">>> 5. Konfigurasi vSwitch Standard"
esxcli network vswitch standard list
echo ""
esxcli network vswitch standard portgroup list
echo ""

echo ">>> 6. Adapter Storage"
esxcli storage core adapter list
echo ""
echo ">>> Perangkat Storage (20 pertama)"
esxcli storage core device list | head -40
echo ""

echo ">>> 7. Status Sertifikat Host"
if [ -f /etc/vmware/ssl/rui.crt ]; then
  echo "Sertifikat host ditemukan."
  openssl x509 -in /etc/vmware/ssl/rui.crt -noout -subject -issuer -dates 2>/dev/null || echo "Tidak dapat parse sertifikat dengan openssl"
else
  echo "Tidak ada sertifikat host (host standalone atau belum bergabung dengan vCenter)"
fi
ls -la /etc/vmware/ssl/ 2>/dev/null
echo ""

echo ">>> 8. Status Sistem"
esxcli system maintenanceMode get
esxcli system stats uptime get
esxcli network firewall get
echo ""

echo ">>> 9. Profil Software Saat Ini"
esxcli software profile get
echo ""

echo "=== Verifikasi selesai ==="
echo "File log: $LOGFILE"
echo ""
echo "Langkah selanjutnya yang disarankan:"
echo "1. Periksa driver yang mungkin hilang (terutama PERC dan NIC)."
echo "2. Jika PERC hilang, pertimbangkan menyalin VIB yang kompatibel dari instalasi ESXi 7."
echo "3. Gabungkan host ke vCenter dan verifikasi kepercayaan sertifikat."
echo "4. Pantau /var/log/vmkernel.log selama 24-48 jam pertama."

Cara menjalankan skrip:

bash
# Enable SSH: Host Client → Manage → Services → TSM-SSH → Start
# Copy script ke host, kemudian:
chmod +x post_esxi8_unsupported_check.sh
sh post_esxi8_unsupported_check.sh
6

Keamanan, CVE & Ransomware Defense

6.1 Ringkasan Status Versi & CVE Kritis

Berikut adalah status patch keamanan ESXi 8.0 hingga Agustus 2026 yang relevan untuk lingkungan lab unsupported:

BuildRilisStatusCVE UtamaCatatan
U3k (25595708)29 Jul 2026FixedCVE-2026-47876 (CVSS 9.3), CVE-2026-41709 (CVSS 2.7)Lengkap. Patch terbaru untuk jalur U3.
U3j (25429389)27 Mei 2026PartialCVE-2026-41709 (CVSS 2.7)Belum memperbaiki CVE-2026-47876 (critical VMXNET3).
U3i (25205845)24 Feb 2026PartialCVE-2026-41703Sudah perbaiki CVE-2026-41703, tapi belum CVE-2026-47876.
U2f (25626445)2025PartialCVE-2026-47876Security-only patch untuk U2 branch. Update resmi ke U3k.
U2e (~24789317)Jul 2025VulnerableCVE-2026-47876, VMSA-2025-0013Sangat rentan. Jangan gunakan untuk produksi.
6.2 CVE Kritis yang Relevan
VMSA-2026-0006 — CVE-2026-47876 (Critical, CVSS 9.3)
Out-of-bounds write pada VMXNET3 virtual NIC. Hanya mempengaruhi VM yang menggunakan adapter VMXNET3. Attacker dengan local admin privilege di dalam VM bisa melakukan VM escape dan eksekusi kode di host ESXi. Belum ada indikasi resmi eksploitasi di wild, namun history ransomware targeting ESXi (CVE-2025-2222x series) menunjukkan risiko tinggi. Fix tersedia di ESXi 8.0 U3k (Build 25595708).
VMSA-2025-0004 — CVE-2025-22224 / CVE-2025-22225 / CVE-2025-22226 (Critical)
Tiga kerentanan zero-day yang dieksploitasi aktif di lingkungan produksi:
  • CVE-2025-22224 (CVSS 9.3) — TOCTOU heap overflow pada VMCI, memungkinkan code execution sebagai VMX process
  • CVE-2025-22225 (CVSS 8.2) — Arbitrary write pada ESXi, memungkinkan sandbox escape dari VMX ke kernel. Dikonfirmasi CISA dieksploitasi ransomware (Februari 2026).
  • CVE-2025-22226 (CVSS 7.1) — Out-of-bounds read pada HGFS, memungkinkan memory leak dari VMX process
Exploit toolkit (ESXicape / VSOCKpuppet) dapat melarikan diri dari VM ke hypervisor.
CVE Lainnya (Lower Severity)
CVE-2026-41703 (Important) — Out-of-bounds read, diperbaiki di U3i.
CVE-2026-41709 (CVSS 2.7, Low) — Insufficient logging, admin jahat bisa melakukan operasi tanpa tercatat di log. Diperbaiki di U3j.
CVE-2026-59309 & CVE-2026-59310 (Critical 9.8) — Lebih ke vCenter (auth bypass & directory traversal), impact ke environment vSphere secara keseluruhan.
6.3 Mitigasi & Defense-in-Depth

Broadcom secara resmi menyatakan tidak ada workaround lengkap yang menghilangkan kerentanan ini sepenuhnya — patching ke fixed build adalah cara yang direkomendasikan. Namun, berikut langkah-langkah praktis yang bisa dilakukan segera:

6.3.1 Patch ke Versi Fixed (Prioritas Utama)
  • Dari U3j atau lebih baru: Langsung ke ESXi 8.0 U3k (Build 25595708) atau lebih baru.
  • Dari U2e: Ke ESXi 8.0 U2f (Build 25626445) — security-only patch untuk CVE-2026-47876, lalu rencanakan ke U3k.
  • Dari U3 lama (U3a–U3c): Jangan lakukan back-in-time update ke U3 yang lebih lama. Langsung ke U3k.
  • Gunakan vSphere Lifecycle Manager (vLCM) image atau offline depot. Live Patch tersedia di U3k untuk cluster yang dikelola oleh images (kurangi downtime).
  • Pastikan backup konfigurasi host + snapshot/backup VM sebelum patching.
6.3.2 Kurangi Attack Surface VMXNET3 (Mitigasi Parsial)
  • Audit semua VM: Ganti VMXNET3 ke E1000e atau VMXNET2 jika performa network tidak kritis (atau test dulu). Non-VMXNET3 tidak affected oleh CVE-2026-47876.
  • Catatan: Broadcom tetap merekomendasikan patch host, bukan hanya ganti adapter.
  • Least privilege di guest OS: Jangan biarkan user biasa jadi local admin di VM production. VMX escape memerlukan privilege admin di dalam VM.
6.3.3 Hardening Host & Network
  • Disable services yang tidak perlu: SLP sudah default disabled di 8.0, pastikan tetap off.
  • Firewall ESXi: Batasi akses management (443, 902, dll) hanya dari jump host / management network terpercaya.
  • Enable Lockdown Mode (Normal atau Strict).
  • Gunakan Secure Boot jika memungkinkan.
  • Isolasi management network dari production/VM network.
  • Monitor log ESXi + vCenter secara real-time (syslog ke SIEM). Perhatikan anomali privilege escalation atau process di host.
6.3.4 Kontrol Akses & Monitoring
  • MFA di vCenter + AD integration yang ketat.
  • Role-based access: Jangan kasih Administrator full di ESXi kecuali benar-benar perlu.
  • Enable auditing & advanced logging.
  • Immutable backup: Backup VM & host config ke air-gapped atau Object Lock. Ransomware ESXi sering target datastore.
  • Update microcode Intel Xeon E5-26xx — ESXi membawa update microcode di patch, pastikan build terbaru.
  • Review Dell firmware/iDRAC — pastikan BIOS/BMC terbaru untuk secure boot & hardware security.
  • Waspadai AD group "ESX Admins" (CVE lama yang pernah dieksploitasi ransomware).
6.3.5 Mode Aman: IP Lokal & Pengamanan Router (Cisco / Fortinet)

Untuk lingkungan lab unsupported yang tetap butuh akses jaringan, terapkan pola defense-in-depth dengan management network yang terisolasi dan perangkat edge firewall/router yang mengontrol akses ke host ESXi.

6.3.5.1 Konfigurasi IP Lokal Terisolasi
  • Management network terpisah: Gunakan VLAN khusus atau interface fisik terdedikasi untuk management ESXi (default: 443/902). Jangan campur dengan VM network atau storage network.
  • IP statik pada management: Set IP address statik di ESXi management interface. Hindari DHCP yang bisa berubah dan memutus akses.
  • Jump host / Bastion host: Hanya jump host yang memiliki route ke management network. Semua admin harus melewati jump host untuk mengakses ESXi host client atau SSH.
  • Disable unnecessary services: Matikan SSH, ESXi Shell, dan CIM broker jika tidak digunakan. Enable hanya saat troubleshooting.
  • Lockdown Mode: Enable Lockdown Mode (Normal atau Strict) di ESXi untuk membatasi direct ESXi CLI access.
6.3.5.2 Tata Cara Pengamanan dengan Router/Firewall Cisco atau Fortinet

Jika di atas host ESXi ada router/firewall seperti Cisco ASA, Cisco ISR, Fortinet FortiGate, atau FortiSwitch, gunakan device tersebut sebagai single point of kontrol untuk management traffic.

Cisco Router/Firewall
Cisco IOS / IOS-XE
! Buat VLAN management terdedikasi
vlan 100
 name ESXI-MGMT

! Interface untuk ESXi management
interface GigabitEthernet0/1
 description ESXi Host Management
 switchport mode access
 switchport access vlan 100
 no shutdown

! ACL untuk membatasi akses management ESXi
ip access-list extended ESXI-MGMT-ACCESS
 permit tcp JUMP-HOST-IP 0.0.0.0 ESXI-MGMT-IP 0.0.0.0 eq 443
 permit tcp JUMP-HOST-IP 0.0.0.0 ESXI-MGMT-IP 0.0.0.0 eq 902
 permit icmp JUMP-HOST-IP 0.0.0.0 ESXI-MGMT-IP 0.0.0.0
 deny   ip any ESXI-MGMT-SUBNET 0.0.0.255
 permit ip any any

! Terapkan ACL di interface
interface GigabitEthernet0/1
 ip access-group ESXI-MGMT-ACCESS in

! Opsional: Port security
switchport port-security
 switchport port-security maximum 2
 switchport port-security violation restrict
Fortinet FortiGate / FortiSwitch
FortiOS CLI
! Buat interface/zone untuk ESXi management
config system interface
    edit "ESXI-MGMT"
        set ip 192.168.10.1/24
        set allowaccess ping https ssh
    next
end

! Firewall policy: hanya izinkan dari jump host ke ESXi
config firewall policy
    edit 1
        set name "Allow-ESXi-MGMT-From-JumpHost"
        set srcintf "LAN"
        set dstintf "ESXI-MGMT"
        set srcaddr "JumpHost_IP"
        set dstaddr "ESXi_Host_IP"
        set action accept
        set service HTTPS SSH ICMP
        set logtraffic all
    next
    edit 2
        set name "Deny-ESXi-MGMT-From-All"
        set srcintf "LAN"
        set dstintf "ESXI-MGMT"
        set srcaddr "all"
        set dstaddr "all"
        set action deny
        set logtraffic all
    next
end

! Opsional: IPS/IDS untuk proteksi tambahan
config ips sensor
    edit "ESXi-Protection"
        config signature
            edit 1
                set action block
            next
        end
    next
end
6.3.5.3 Verifikasi Koneksi Management

Setelah konfigurasi router/firewall, verifikasi koneksi dari jump host ke ESXi:

bash
# Dari jump host, test koneksi ke ESXi management
ping ESXI-MGMT-IP
nc -zv ESXI-MGMT-IP 443
nc -zv ESXI-MGMT-IP 902

# Verifikasi di ESXi host bahwa hanya IP jump host yang bisa akses
esxcli network firewall get
esxcli network firewall ruleset list | grep -i http
esxcli network firewall ruleset list | grep -i ssh
6.3.5.4 Catatan Penting
  • Jangan expose ESXi management ke internet. Management interface hanya boleh diakses dari jump host / management VLAN terpercaya.
  • Gunakan VPN jika perlu mengakses lab dari luar. Jangan buka port 443/902 ke publik.
  • Monitoring: Aktifkan logging di router/firewall untuk mencatat semua koneksi ke management ESXi. Monitor untuk brute force attempts.
  • Change default credentials: Ganti password root default ESXi setelah instalasi. Gunakan SSH key-based authentication.
  • Backup firewall config: Ekspor konfigurasi router/firewall secara berkala. Jika device compromised, Anda bisa restore ke state yang bersih.
6.4 Troubleshooting Serangan Ransomware / Breach
  1. Isolasi segera: Putuskan konektivitas jaringan host ESXi dan migrasi VM jika memungkinkan.
  2. Jangan reboot sembarang: Reboot bisa menghapus bukti forensik dari memory. Catat semua gejala terlebih dahulu.
  3. Periksa VMCI: Jika driver vmci dimuat oleh proses mencurigakan, ini bisa jadi indikasi ESXicape exploit.
  4. Verifikasi VIB: Jalankan esxcli software vib list dan bandingkan dengan known-good baseline.
  5. Cek backdoor VSOCK: Periksa apakah ada proses VSOCK yang tidak dikenal dengan esxcli network vsock list.
  6. Rollback: Boot dari ISO rescue, pulihkan dari backup, atau lakukan fresh install dari scratch.
  7. Pelajari fallback: Jika ESXi terus-menerus menjadi target karena hardware legacy, pertimbangkan migrasi ke Proxmox VE 9 (section 9).
7

Troubleshooting Masalah Umum

MasalahGejalaTindakan yang Direkomendasikan
Unsupported CPU — 12G Installer berhenti dengan CPU_SUPPORT_ERROR atau CPU_SUPPORT_WARNING Tekan Shift + O saat boot, tambahkan allowLegacyCPU=true, lalu Enter. Untuk ESXi 8.0 U2+, pastikan CPU mendukung XSAVE.
Unsupported CPU — 11G (Westmere) Installer gagal total meskipun allowLegacyCPU=true diberikan PowerEdge 11G (R510/R610/R710/R810/R910) menggunakan Intel Xeon 5600/7500 series (Westmere-EP, CPUID 0x000206C1) yang tidak mendukung XSAVE. ESXi 8.0 U2+ tidak bisa diinstal. Gunakan ESXi 6.7/7.0 atau pindah ke Proxmox VE 9.
PERC controller tidak terdeteksi Tidak ada local datastores, esxcli storage core adapter list empty Copy compatible VIB dari ESXi 7 host ke /bootbank, edit /bootbank/boot.cfg, tambahkan VIB ke module list, reboot.
Network adapter missing esxcli network nic list empty Update NIC firmware via iDRAC; install community VIB untuk chipset tertentu (igb/ixgbe/bnx/tg3/e1000).
Host gagal boot setelah reboot Purple Screen of Death (PSOD) / hangs Boot dari ISO lagi dengan allowLegacyCPU=true, inspect dan perbaiki /bootbank/boot.cfg. Pastikan tidak ada corrupted VIB.
Secure Boot / signature issues PSOD terkait unsigned modules Dinonaktifkan Secure Boot sementara atau set /UserVars/ExecInstalledOnly ke 0 (lab only).
Disk di belakang PERC tidak terlihat Installer tidak menampilkan target disk Pastikan virtual disk dibuat di PERC dan Firmware Device Order (FDO) dinonaktifkan.
Certificate problems setelah join vCenter Trust warnings di vCenter Regenerate host certificates atau import vCenter root CA ke host.
Link flapping / performance issues Jaringan tidak stabil, koneksi terputus Update NIC firmware dan drivers; periksa kabel fisik dan konfigurasi switch.
Ransomware / VM escape suspicion Host tidak dapat diakses, VM terenkripsi Isolasi jaringan, jangan reboot, periksa VMCI/Virtual sockets, rollback dari backup, fresh install jika perlu.
Tips Stabilisasi Tambahan
  • Setelah boot berhasil, dokumentasikan profil image dan VIB yang terinstal secara akurat.
  • Monitor logs (/var/log/vmkernel.log, /var/log/vobd.log) dengan seksama selama 48 jam pertama.
  • Hindari menaruh workload produksi pada konfigurasi ini.
  • Rencanakan migrasi ke hardware yang didukung secara resmi sedari dini.
  • Terapkan patch keamanan Broadcom VMSA-2025-0004 dan VMSA-2026-0006 segera.
8

Rollback Plan

  1. Simpan original ESXi 7 installation media dan konfigurasi backup.
  2. Jika upgrade gagal secara kritis, boot dari ESXi 7 ISO dan lakukan fresh install atau restore dari backup.
  3. Restore VM dari pre-upgrade backups.
  4. Jika EFI/Boot manager rusak, gunakan ESXi rescue mode dari ISO untuk memperbaiki boot.cfg atau bootbank.
9

Rekomendasi Fallback: Proxmox VE 9

Jika semua langkah di atas gagal dan ESXi 8.0 tidak dapat dipaksa berjalan pada hardware legacy, pertimbangkan migrasi ke Proxmox VE 9. Proxmox VE 9 berbasis Debian 13 Trixie memiliki kompatibilitas hardware yang lebih luas, termasuk penuh terhadap Dell PowerEdge generasi ke-12 dengan Intel Xeon E5-2600 series. Tidak ada batasan CPU deprecated seperti VMware, dan Anda mendapatkan fitur enterprise seperti ZFS, LVM-thin, Ceph, dan live migration secara gratis.

Tutorial lengkap instalasi Proxmox VE 9 tersedia di:

Proxmox VE 9 mendukung instalasi clean pada R520, R620, R720, R720xd, R820, dan R920 tanpa workaround kernel. Gunakan Rufus/DD mode untuk membuat USB installer, boot dalam mode UEFI, pilih filesystem ext4 atau ZFS sesuai kebutuhan, dan akses web interface di https://<IP>:8006.

10

Referensi

  • VMware / Broadcom KB 82794 – CPU Support Deprecation and Discontinuation
  • Broadcom KB 318697 – CPU Support Deprecation and Discontinuation In VCF Releases (Updated Juli 2026)
  • Broadcom KB 391610 – ESXi patch/upgrade failed with CPU_SUPPORT_WARNING
  • VMSA-2025-0004 – VMware ESXi, Workstation, Fusion updates address multiple vulnerabilities (CVE-2025-22224, CVE-2025-22225, CVE-2025-22226)
  • VMSA-2026-0006 – ESXi 8.0 U3k resolves CVE-2026-47876
  • CISA KEV Catalog – CVE-2025-22225 known to be used in ransomware campaigns
  • Huntress Analysis – ESXi VM Escape Exploit Toolkit (ESXicape) / VSOCKpuppet
  • Broadcom Support Portal – VMware vSphere 8.0 Custom ISO (Dell)
  • Dell Knowledge Base – How to Download and Use Dell Customized VMware ESXi Images
  • Dell 12G PowerEdge Portfolio Comparison (R520/R620/R720/R720xd/R820/R920)
  • Community workarounds for allowLegacyCPU=true (William Lam, vInfrastructure Blog, etc.)
  • Proxmox VE 9 Installation Guide — https://alsyundawy.com/Proxmox-VE-9.html
Penafian — Dokumen ini disediakan untuk tujuan pendidikan dan lab only. Penulis dan pihak terkait tidak bertanggung jawab atas kehilangan data, downtime, atau konsekuensi lain yang timbul dari penggunaan prosedur ini pada hardware yang tidak didukung. Selalu test secara menyeluruh di lingkungan non-produksi terlebih dahulu.