Skip to content

NFS and Mounting

NFS (Network File System) allows different hosts to share directories and files over the network. It is one of the most commonly used network storage sharing protocols in Linux/Unix environments, widely used for cluster shared storage, development environment collaboration, centralized log storage, and more.

NFS Server NFS Client
/data/shared ----network export----> /mnt/nfs_share (mount point)
192.168.1.10 192.168.1.20
Terminal window
sudo dnf install nfs-utils -y
Terminal window
sudo systemctl enable --now nfs-server

Verify the service status:

Terminal window
sudo systemctl status nfs-server
Terminal window
sudo mkdir -p /data/shared
sudo chown nobody:nobody /data/shared
sudo chmod 755 /data/shared

/etc/exports is the core NFS configuration file that defines which directories are shared with which clients and the associated permissions.

Terminal window
sudo vi /etc/exports

Add an export entry:

/data/shared 192.168.1.0/24(rw,sync,no_root_squash,no_subtree_check)

Basic format:

shared_directory client_address(option1,option2,...)

Client address formats:

FormatDescriptionExample
Single IPAllow only one host192.168.1.20
SubnetAllow an entire subnet192.168.1.0/24
HostnameSpecify a hostnameclient.example.com
WildcardMatch domain names*.example.com
AllAllow all hosts*

Common options:

OptionDescription
rwRead-write access
roRead-only access
syncSynchronous writes; higher data safety
asyncAsynchronous writes; better performance but less safe
no_root_squashClient root has root privileges on the server
root_squashClient root is mapped to nobody (default)
all_squashAll users are mapped to nobody
anonuid=NMap anonymous users to the specified UID
anongid=NMap anonymous users to the specified GID
no_subtree_checkDo not check subdirectory permissions; improves performance
# Read-write share, allow entire subnet
/data/shared 192.168.1.0/24(rw,sync,no_subtree_check)
# Read-only share, allow specific hosts
/data/public 192.168.1.0/24(ro,sync,no_subtree_check)
# Multiple clients with different permissions
/data/project 192.168.1.20(rw,sync,no_root_squash) 192.168.1.30(ro,sync)
# Map all users to a specified UID/GID
/data/upload *(rw,sync,all_squash,anonuid=1000,anongid=1000)

After modifying /etc/exports, re-export the shares:

Terminal window
sudo exportfs -ra

View the current export list:

Terminal window
sudo exportfs -v

Common exportfs parameters:

ParameterDescription
-aExport or unexport all directories
-rRe-export all directories
-vVerbose output
-sShow the current export list

NFS requires multiple ports to be open in order to function properly. Using firewalld service rules is the simplest approach.

Terminal window
sudo firewall-cmd --permanent --add-service=nfs
sudo firewall-cmd --permanent --add-service=rpc-bind
sudo firewall-cmd --permanent --add-service=mountd
sudo firewall-cmd --reload
Terminal window
sudo firewall-cmd --list-all
Terminal window
sudo dnf install nfs-utils -y
Terminal window
showmount -e 192.168.1.10
Terminal window
sudo mkdir -p /mnt/nfs_share
sudo mount -t nfs 192.168.1.10:/data/shared /mnt/nfs_share

Verify the mount:

Terminal window
df -hT /mnt/nfs_share
mount | grep nfs
Terminal window
# Use NFS v4
sudo mount -t nfs -o vers=4 192.168.1.10:/data/shared /mnt/nfs_share
# Use NFS v3
sudo mount -t nfs -o vers=3 192.168.1.10:/data/shared /mnt/nfs_share
Terminal window
sudo umount /mnt/nfs_share

Edit /etc/fstab:

Terminal window
sudo vi /etc/fstab

Add:

192.168.1.10:/data/shared /mnt/nfs_share nfs defaults,_netdev 0 0
192.168.1.10:/data/shared /mnt/nfs_share nfs rw,hard,timeo=600,retrans=2,_netdev 0 0
OptionDescription
_netdevMarks as a network device; mount only after the network is ready
hardContinuously retry when the server is unresponsive (default)
softReturn an error after timeout when the server is unresponsive
timeo=NTimeout value (in units of 0.1 seconds)
retrans=NNumber of retries
rsize=NRead buffer size
wsize=NWrite buffer size
vers=4Specify the NFS version
noatimeDo not update access times
nosuidDisable SUID
noexecDisable execution
Terminal window
sudo mount -a
df -hT /mnt/nfs_share

autofs automatically mounts NFS shares when a directory is accessed and automatically unmounts them when idle, reducing resource usage.

Terminal window
sudo dnf install autofs -y
  1. Edit the master configuration file /etc/auto.master and add an auto-mount point:

    Terminal window
    sudo vi /etc/auto.master

    Add the following line:

    /mnt/auto /etc/auto.nfs --timeout=300

    This means subdirectories under /mnt/auto will be automatically mounted according to the rules in /etc/auto.nfs, and automatically unmounted after 300 seconds of inactivity.

  2. Create the map file /etc/auto.nfs:

    Terminal window
    sudo vi /etc/auto.nfs

    Add mapping rules:

    shared -rw,soft,timeo=300 192.168.1.10:/data/shared
    public -ro,soft,timeo=300 192.168.1.10:/data/public

    This means accessing /mnt/auto/shared will automatically mount 192.168.1.10:/data/shared.

  3. Start the autofs service:

    Terminal window
    sudo systemctl enable --now autofs
  4. Verify auto-mounting:

    Terminal window
    # Access the directory to trigger auto-mount
    ls /mnt/auto/shared
    # Check mount status
    mount | grep auto

If you need to automatically mount all exported directories from the server, you can use a wildcard:

/etc/auto.master
/mnt/auto /etc/auto.nfs --timeout=300
# /etc/auto.nfs
* -rw,soft 192.168.1.10:/data/&

& is replaced by the subdirectory name being accessed. For example, accessing /mnt/auto/shared will automatically mount 192.168.1.10:/data/shared.

Using autofs to Mount User Home Directories

Section titled “Using autofs to Mount User Home Directories”

NFS + autofs is commonly used to centrally manage user home directories:

/etc/auto.master
/home /etc/auto.home --timeout=600
# /etc/auto.home
* -rw,soft nfs-server:/home/&

When a user logs in, their home directory /home/username is automatically mounted from the NFS server.

Terminal window
# Check network connectivity
ping 192.168.1.10
# Check if the NFS service is running
sudo systemctl status nfs-server # Run on the server
# Check RPC services
rpcinfo -p 192.168.1.10
# Check server export list
showmount -e 192.168.1.10
# Check the firewall
sudo firewall-cmd --list-all # Run on the server
Terminal window
# Server statistics
nfsstat -s
# Client statistics
nfsstat -c
# View mounted NFS information
nfsstat -m
Terminal window
# View NFS versions supported by the server
cat /proc/fs/nfsd/versions
# View the version used by the client mount
nfsstat -m
  1. Install and start the NFS service:

    Terminal window
    sudo dnf install nfs-utils -y
    sudo systemctl enable --now nfs-server
  2. Create shared directories:

    Terminal window
    sudo mkdir -p /data/shared /data/readonly
    sudo chown nobody:nobody /data/shared
    sudo chmod 755 /data/shared /data/readonly
  3. Configure exports:

    Terminal window
    cat <<EOF | sudo tee /etc/exports
    /data/shared 192.168.1.0/24(rw,sync,no_subtree_check)
    /data/readonly 192.168.1.0/24(ro,sync,no_subtree_check)
    EOF
    sudo exportfs -ra
    sudo exportfs -v
  4. Configure the firewall:

    Terminal window
    sudo firewall-cmd --permanent --add-service=nfs
    sudo firewall-cmd --permanent --add-service=rpc-bind
    sudo firewall-cmd --permanent --add-service=mountd
    sudo firewall-cmd --reload
  1. Install NFS tools:

    Terminal window
    sudo dnf install nfs-utils autofs -y
  2. Verify server exports:

    Terminal window
    showmount -e 192.168.1.10
  3. Create mount points and mount via fstab:

    Terminal window
    sudo mkdir -p /mnt/shared /mnt/readonly
    cat <<EOF | sudo tee -a /etc/fstab
    192.168.1.10:/data/shared /mnt/shared nfs rw,_netdev,hard 0 0
    192.168.1.10:/data/readonly /mnt/readonly nfs ro,_netdev,hard 0 0
    EOF
    sudo mount -a
    df -hT /mnt/shared /mnt/readonly
  4. Test reading and writing:

    Terminal window
    echo "NFS test" | sudo tee /mnt/shared/test.txt
    cat /mnt/shared/test.txt

NFS is a simple and efficient shared storage solution for enterprise environments. Properly configuring permissions, options, and firewall rules, combined with autofs for on-demand mounting, enables a flexible and reliable network storage infrastructure.