Updated: 28 September 2026 · Applies to: nfs-utils 2.5 to 2.8 on AlmaLinux and Rocky Linux 9 and 10 and RHEL 9 and 10; nfs-kernel-server on Ubuntu 24.04 and 26.04 and Debian 13 (NFS 4.2)
NFS (Network File System) lets Linux servers share folders over the network: one server exports a folder, and others mount it as if it were a local disk. It is common for shared web content, backups and home folders on a private network. This guide sets up a server and a client with NFS version 4.2, the default on current systems. It replaces the older CentOS 6 and 7 version of the guide.
Security first
NFS trusts the client's user IDs and is meant for private networks. Never export to the whole internet: allow only specific client addresses, ideally over a private network or VPN between your servers.
Set up the NFS server
- Install the server package:
dnf install nfs-utils # AlmaLinux, Rocky Linux, RHEL apt install nfs-kernel-server # Ubuntu, Debian
- Create the folder to share and set its owner:
mkdir -p /srv/share chown nobody:nobody /srv/share # on Ubuntu and Debian: nobody:nogroup
- Export it to your client in
/etc/exports(one line per folder):/srv/share 10.0.0.21(rw,sync,no_subtree_check)
Use a subnet such as10.0.0.0/24for several clients. Do not put a space between the address and the bracket. - Start the server and load the exports:
systemctl enable --now nfs-server exportfs -rav
On Ubuntu and Debian the service is also callednfs-server(aliasnfs-kernel-server). - Open the firewall for the client only. NFS 4 needs just TCP port 2049:
firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="10.0.0.21/32" service name="nfs" accept' firewall-cmd --reload
With UFW:ufw allow from 10.0.0.21 to any port 2049 proto tcp.
Set up the client
- Install the client tools:
dnf install nfs-utils # AlmaLinux, Rocky Linux, RHEL apt install nfs-common # Ubuntu, Debian
- Mount the share:
mkdir -p /mnt/share mount -t nfs 10.0.0.20:/srv/share /mnt/share df -h /mnt/share
- Mount it at every boot by adding a line to
/etc/fstab:10.0.0.20:/srv/share /mnt/share nfs defaults,_netdev,nofail 0 0
_netdevwaits for the network, andnofaillets the client boot even if the server is down. Test withumount /mnt/share && mount -a.
Useful export options
rworro: read-write or read-only.sync: the server confirms writes only after they are on disk. Safer thanasync, which is faster but can lose data if the server crashes.root_squash(default): root on the client becomesnobodyon the server.no_root_squashremoves this protection; use it only for trusted clients such as a backup server.all_squashwithanonuid=andanongid=: map every client user to one server user, useful for shared upload folders.
Check and troubleshoot
- On the server,
exportfs -vshows the active exports and options. - On the client,
nfsstat -mshows mounted shares and the NFS version in use. - "access denied by server while mounting": see how to fix mount.nfs: access denied by server.
- Files owned by
nobodyor wrong users: user IDs differ between the machines. Use the same UID and GID for shared users on all servers.
Official documentation: Deploying an NFS server (Red Hat) and exports manual page.
Ucartz services for this topic
- KVM VPS hosting: NVMe SSD and full root access, with Free Basic Managed Support.
- Unmanaged dedicated servers: full root access and free IPMI KVM, with Free Basic Managed Support.
- Linux server management: hardening, patching, monitoring and automation for Ubuntu, Debian, RHEL and AlmaLinux.
