Is there any recommendation regarding next options:
Putting PAM servers on different ESXi hosts
Putting both PAM servers on the same ESXi host
PAM 4.1.x
Customer is very worried and ask this because the single-site cluster could be sensitive from synchronization loss.
Generally the only suggestion is to not run all your nodes on the same esx host within the ESX cluster.. But if client is serious about fault tolerance then he should have 3 nodes.
If you only want 2 nodes you will not have an fault tolerance
https://techdocs.broadcom.com/us/en/symantec-security-software/identity-security/privileged-access-manager/4-1-6/deploying/set-up-a-cluster/cluster-synchronization-promotion-and-recovery/primary-site-fault-tolerance.html
and
https://techdocs.broadcom.com/us/en/symantec-security-software/identity-security/privileged-access-manager/4-1-6/deploying/set-up-a-cluster/cluster-synchronization-promotion-and-recovery.html