VxRail: Hosts Show Alert in vCenter Stating: TPM 2.0 Device Detected But a Connection Cannot Be Established (Customer Correctable)

Summary: Hosts show alerts stating: Trusted Platform Module (TPM) 2.0 device detected but a connection cannot be established.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

ESXi hosts in the cluster have an alert which states: TPM 2.0 device detected but a connection cannot be established.

 

Cause

The ESXi host's BIOS must be configured to use the SHA256 hashing algorithm in order to support TPM. The alert can result from the advanced BIOS settings of the ESXi host not being set to the default of SHA1 or other BIOS settings. 

 

Resolution

***Check that these BIOS changes outlined in this article are appropriate for your specific environment***.

The steps below are to be performed on each affected node, one at a time. Before placing nodes into Maintenance Mode, ensure that the cluster is healthy. Ensure that there is not an active vSan resynchronization, and that there are adequate resources available for virtual machine (VM) Migration. Ensure that enough free VSAN space is available for fault tolerance.

  1. Place the host into Maintenance Mode in vCenter using 'Ensure Accessibility'.
  2. Use IDRAC or BMC to open a console to the host. Reboot the host and enter BIOS settings, when available, by pressing F2 for System Setup > System BIOS
  3. Go to the boot settings and take the screenshot for the UEFI Boot Sequence.
  4. Reset BIOS settings to default by clicking the "Default" button. (Note: Resetting the BIOS setting to default may change the BIOS boot order.)

Screenshot of the bios menu 
 
5. Enter System Security.
   a. 'TPM Security' should be 'On'.
   b. 'TxT' should be 'On'.

Screenshot of the TPM options in bios 
 

!!!! Note!!!!
If there is only the Off option at Intel TXT field, set Secure boot enabled using KB#000158364  and set SHA-256 (Step 6 of this KB) first, then turn Intel(R) TXT on.
Article 000158364 requires other changes, log a service request with Dell Technologies.

Screenshot of the TXT option in bios 


6. Enter 'TPM Advanced Settings'.
   a. TPM PPI settings should be 'Disable'.
   b. 'TPM2 Algorithm Selection' should be 'SHA256'.
Screenshot of the advanced TPM options in bios 
7. Verify that Secure Boot is set to "Enabled."
Screenshot of the Secure Boot setting in bios 
8. Verify that BIOS settings are correct. 
9. Go to the Boot settings -->UEFI Boot Sequence and change the boot order again as per your taken screenshot. (Generally AHCI controller in…: ESXi operating system is the first boot)
10. Exit the BIOS settings, which will reboot the node. Wait for the node to boot completely.
11. In vCenter, if the host shows disconnected, right-click the host icon, select 'Connection' and reconnect the host before exiting Maintenance Mode.
12. Clear any alerts, retest, check once again for overall cluster health, VSAN resynchronization, sufficient resources available, and go to the next host. 

Additional Information

If it is not possible to change the TPM algorithm to SHA256, try it with Intel(R) TXT disabled.
If there is still an alarm even after reboot, disconnect and then reconnect the host from vCenter. 

**** No need to put the host into maintenance mode when disconnecting the host from vCenter.

Affected Products

VxRail, VxRail 460 and 470 Nodes, VxRail Appliance Series, VxRail G Series Nodes, VxRail D Series Nodes, VxRail D560, VxRail D560F, VxRail E Series Nodes, VxRail E460, VxRail E560, VxRail E560F, VxRail E560N, VxRail E660, VxRail E660F, VxRail E660N , VxRail E665, VxRail E665F, VxRail E665N, VxRail G560, VxRail G560F, VxRail P Series Nodes, VxRail P470, VxRail P570, VxRail P570F, VxRail P580N, VxRail P670F, VxRail P670N, VxRail P675F, VxRail P675N, VxRail S Series Nodes, VxRail S470, VxRail S570, VxRail S670, VxRail Software, VxRail V Series Nodes, VxRail V470, VxRail V570, VxRail V570F, VXRAIL V670F, VxRail VD-4510C, VxRail VD-4520C, VxRail VD Series Nodes, VxRail VE-660, VxRail VE-6615, VxRail VP-760, VxRail VP-7625, VxRail VS-760 ...
Article Properties
Article Number: 000172501
Article Type: Solution
Last Modified: 03 Jun 2025
Version:  7
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.