NFS and Mounting
NFS (Network File System) allows different hosts to share directories and files over the network. It is one of the most commonly used network storage sharing protocols in Linux/Unix environments, widely used for cluster shared storage, development environment collaboration, centralized log storage, and more.
NFS Basic Architecture
Section titled “NFS Basic Architecture”NFS Server NFS Client/data/shared ----network export----> /mnt/nfs_share (mount point)192.168.1.10 192.168.1.20NFS Server Configuration
Section titled “NFS Server Configuration”Installing the NFS Service
Section titled “Installing the NFS Service”sudo dnf install nfs-utils -yStarting and Enabling at Boot
Section titled “Starting and Enabling at Boot”sudo systemctl enable --now nfs-serverVerify the service status:
sudo systemctl status nfs-serverCreating a Shared Directory
Section titled “Creating a Shared Directory”sudo mkdir -p /data/sharedsudo chown nobody:nobody /data/sharedsudo chmod 755 /data/sharedConfiguring /etc/exports
Section titled “Configuring /etc/exports”/etc/exports is the core NFS configuration file that defines which directories are shared with which clients and the associated permissions.
sudo vi /etc/exportsAdd an export entry:
/data/shared 192.168.1.0/24(rw,sync,no_root_squash,no_subtree_check)exports Configuration Details
Section titled “exports Configuration Details”Basic format:
shared_directory client_address(option1,option2,...)Client address formats:
| Format | Description | Example |
|---|---|---|
| Single IP | Allow only one host | 192.168.1.20 |
| Subnet | Allow an entire subnet | 192.168.1.0/24 |
| Hostname | Specify a hostname | client.example.com |
| Wildcard | Match domain names | *.example.com |
| All | Allow all hosts | * |
Common options:
| Option | Description |
|---|---|
rw | Read-write access |
ro | Read-only access |
sync | Synchronous writes; higher data safety |
async | Asynchronous writes; better performance but less safe |
no_root_squash | Client root has root privileges on the server |
root_squash | Client root is mapped to nobody (default) |
all_squash | All users are mapped to nobody |
anonuid=N | Map anonymous users to the specified UID |
anongid=N | Map anonymous users to the specified GID |
no_subtree_check | Do not check subdirectory permissions; improves performance |
Multiple Directory Export Examples
Section titled “Multiple Directory Export Examples”# Read-write share, allow entire subnet/data/shared 192.168.1.0/24(rw,sync,no_subtree_check)
# Read-only share, allow specific hosts/data/public 192.168.1.0/24(ro,sync,no_subtree_check)
# Multiple clients with different permissions/data/project 192.168.1.20(rw,sync,no_root_squash) 192.168.1.30(ro,sync)
# Map all users to a specified UID/GID/data/upload *(rw,sync,all_squash,anonuid=1000,anongid=1000)Applying Export Configuration
Section titled “Applying Export Configuration”After modifying /etc/exports, re-export the shares:
sudo exportfs -raView the current export list:
sudo exportfs -vCommon exportfs parameters:
| Parameter | Description |
|---|---|
-a | Export or unexport all directories |
-r | Re-export all directories |
-v | Verbose output |
-s | Show the current export list |
NFS Firewall Configuration
Section titled “NFS Firewall Configuration”NFS requires multiple ports to be open in order to function properly. Using firewalld service rules is the simplest approach.
Opening NFS-Related Services
Section titled “Opening NFS-Related Services”sudo firewall-cmd --permanent --add-service=nfssudo firewall-cmd --permanent --add-service=rpc-bindsudo firewall-cmd --permanent --add-service=mountdsudo firewall-cmd --reloadVerifying Firewall Rules
Section titled “Verifying Firewall Rules”sudo firewall-cmd --list-allNFS Client Mounting
Section titled “NFS Client Mounting”Installing Client Tools
Section titled “Installing Client Tools”sudo dnf install nfs-utils -yViewing Directories Shared by the Server
Section titled “Viewing Directories Shared by the Server”showmount -e 192.168.1.10Temporary Mount
Section titled “Temporary Mount”sudo mkdir -p /mnt/nfs_sharesudo mount -t nfs 192.168.1.10:/data/shared /mnt/nfs_shareVerify the mount:
df -hT /mnt/nfs_sharemount | grep nfsMounting with a Specific NFS Version
Section titled “Mounting with a Specific NFS Version”# Use NFS v4sudo mount -t nfs -o vers=4 192.168.1.10:/data/shared /mnt/nfs_share
# Use NFS v3sudo mount -t nfs -o vers=3 192.168.1.10:/data/shared /mnt/nfs_shareUnmounting NFS
Section titled “Unmounting NFS”sudo umount /mnt/nfs_sharePersistent NFS Mounting via fstab
Section titled “Persistent NFS Mounting via fstab”Basic fstab NFS Entry
Section titled “Basic fstab NFS Entry”Edit /etc/fstab:
sudo vi /etc/fstabAdd:
192.168.1.10:/data/shared /mnt/nfs_share nfs defaults,_netdev 0 0fstab Entry with Detailed Options
Section titled “fstab Entry with Detailed Options”192.168.1.10:/data/shared /mnt/nfs_share nfs rw,hard,timeo=600,retrans=2,_netdev 0 0Common NFS Mount Options
Section titled “Common NFS Mount Options”| Option | Description |
|---|---|
_netdev | Marks as a network device; mount only after the network is ready |
hard | Continuously retry when the server is unresponsive (default) |
soft | Return an error after timeout when the server is unresponsive |
timeo=N | Timeout value (in units of 0.1 seconds) |
retrans=N | Number of retries |
rsize=N | Read buffer size |
wsize=N | Write buffer size |
vers=4 | Specify the NFS version |
noatime | Do not update access times |
nosuid | Disable SUID |
noexec | Disable execution |
Verifying fstab Configuration
Section titled “Verifying fstab Configuration”sudo mount -adf -hT /mnt/nfs_shareAuto-Mounting with autofs
Section titled “Auto-Mounting with autofs”autofs automatically mounts NFS shares when a directory is accessed and automatically unmounts them when idle, reducing resource usage.
Installing autofs
Section titled “Installing autofs”sudo dnf install autofs -yConfiguring autofs
Section titled “Configuring autofs”-
Edit the master configuration file
/etc/auto.masterand add an auto-mount point:Terminal window sudo vi /etc/auto.masterAdd the following line:
/mnt/auto /etc/auto.nfs --timeout=300This means subdirectories under
/mnt/autowill be automatically mounted according to the rules in/etc/auto.nfs, and automatically unmounted after 300 seconds of inactivity. -
Create the map file
/etc/auto.nfs:Terminal window sudo vi /etc/auto.nfsAdd mapping rules:
shared -rw,soft,timeo=300 192.168.1.10:/data/sharedpublic -ro,soft,timeo=300 192.168.1.10:/data/publicThis means accessing
/mnt/auto/sharedwill automatically mount192.168.1.10:/data/shared. -
Start the autofs service:
Terminal window sudo systemctl enable --now autofs -
Verify auto-mounting:
Terminal window # Access the directory to trigger auto-mountls /mnt/auto/shared# Check mount statusmount | grep auto
autofs Wildcard Mounting
Section titled “autofs Wildcard Mounting”If you need to automatically mount all exported directories from the server, you can use a wildcard:
/mnt/auto /etc/auto.nfs --timeout=300
# /etc/auto.nfs* -rw,soft 192.168.1.10:/data/&& is replaced by the subdirectory name being accessed. For example, accessing /mnt/auto/shared will automatically mount 192.168.1.10:/data/shared.
Using autofs to Mount User Home Directories
Section titled “Using autofs to Mount User Home Directories”NFS + autofs is commonly used to centrally manage user home directories:
/home /etc/auto.home --timeout=600
# /etc/auto.home* -rw,soft nfs-server:/home/&When a user logs in, their home directory /home/username is automatically mounted from the NFS server.
NFS Troubleshooting
Section titled “NFS Troubleshooting”Client Cannot Mount
Section titled “Client Cannot Mount”# Check network connectivityping 192.168.1.10
# Check if the NFS service is runningsudo systemctl status nfs-server # Run on the server
# Check RPC servicesrpcinfo -p 192.168.1.10
# Check server export listshowmount -e 192.168.1.10
# Check the firewallsudo firewall-cmd --list-all # Run on the serverViewing NFS Statistics
Section titled “Viewing NFS Statistics”# Server statisticsnfsstat -s
# Client statisticsnfsstat -c
# View mounted NFS informationnfsstat -mChecking NFS Version
Section titled “Checking NFS Version”# View NFS versions supported by the servercat /proc/fs/nfsd/versions
# View the version used by the client mountnfsstat -mHands-On: Setting Up NFS Shared Storage
Section titled “Hands-On: Setting Up NFS Shared Storage”Server Configuration (192.168.1.10)
Section titled “Server Configuration (192.168.1.10)”-
Install and start the NFS service:
Terminal window sudo dnf install nfs-utils -ysudo systemctl enable --now nfs-server -
Create shared directories:
Terminal window sudo mkdir -p /data/shared /data/readonlysudo chown nobody:nobody /data/sharedsudo chmod 755 /data/shared /data/readonly -
Configure exports:
Terminal window cat <<EOF | sudo tee /etc/exports/data/shared 192.168.1.0/24(rw,sync,no_subtree_check)/data/readonly 192.168.1.0/24(ro,sync,no_subtree_check)EOFsudo exportfs -rasudo exportfs -v -
Configure the firewall:
Terminal window sudo firewall-cmd --permanent --add-service=nfssudo firewall-cmd --permanent --add-service=rpc-bindsudo firewall-cmd --permanent --add-service=mountdsudo firewall-cmd --reload
Client Configuration (192.168.1.20)
Section titled “Client Configuration (192.168.1.20)”-
Install NFS tools:
Terminal window sudo dnf install nfs-utils autofs -y -
Verify server exports:
Terminal window showmount -e 192.168.1.10 -
Create mount points and mount via fstab:
Terminal window sudo mkdir -p /mnt/shared /mnt/readonlycat <<EOF | sudo tee -a /etc/fstab192.168.1.10:/data/shared /mnt/shared nfs rw,_netdev,hard 0 0192.168.1.10:/data/readonly /mnt/readonly nfs ro,_netdev,hard 0 0EOFsudo mount -adf -hT /mnt/shared /mnt/readonly -
Test reading and writing:
Terminal window echo "NFS test" | sudo tee /mnt/shared/test.txtcat /mnt/shared/test.txt
NFS is a simple and efficient shared storage solution for enterprise environments. Properly configuring permissions, options, and firewall rules, combined with autofs for on-demand mounting, enables a flexible and reliable network storage infrastructure.