Updated: 28 September 2026 · Applies to: nfs-utils 2.5 to 2.8 on AlmaLinux and Rocky Linux 9 and 10 and RHEL 9 and 10; nfs-kernel-server on Ubuntu 24.04 and 26.04 and Debian 13 (NFS 4.2)

NFS (Network File System) lets Linux servers share folders over the network: one server exports a folder, and others mount it as if it were a local disk. It is common for shared web content, backups and home folders on a private network. This guide sets up a server and a client with NFS version 4.2, the default on current systems. It replaces the older CentOS 6 and 7 version of the guide.

Security first

NFS trusts the client's user IDs and is meant for private networks. Never export to the whole internet: allow only specific client addresses, ideally over a private network or VPN between your servers.

Set up the NFS server

  1. Install the server package:
    dnf install nfs-utils              # AlmaLinux, Rocky Linux, RHEL
    apt install nfs-kernel-server      # Ubuntu, Debian
  2. Create the folder to share and set its owner:
    mkdir -p /srv/share
    chown nobody:nobody /srv/share     # on Ubuntu and Debian: nobody:nogroup
  3. Export it to your client in /etc/exports (one line per folder):
    /srv/share  10.0.0.21(rw,sync,no_subtree_check)
    Use a subnet such as 10.0.0.0/24 for several clients. Do not put a space between the address and the bracket.
  4. Start the server and load the exports:
    systemctl enable --now nfs-server
    exportfs -rav
    On Ubuntu and Debian the service is also called nfs-server (alias nfs-kernel-server).
  5. Open the firewall for the client only. NFS 4 needs just TCP port 2049:
    firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="10.0.0.21/32" service name="nfs" accept'
    firewall-cmd --reload
    With UFW: ufw allow from 10.0.0.21 to any port 2049 proto tcp.

Set up the client

  1. Install the client tools:
    dnf install nfs-utils        # AlmaLinux, Rocky Linux, RHEL
    apt install nfs-common       # Ubuntu, Debian
  2. Mount the share:
    mkdir -p /mnt/share
    mount -t nfs 10.0.0.20:/srv/share /mnt/share
    df -h /mnt/share
  3. Mount it at every boot by adding a line to /etc/fstab:
    10.0.0.20:/srv/share  /mnt/share  nfs  defaults,_netdev,nofail  0 0
    _netdev waits for the network, and nofail lets the client boot even if the server is down. Test with umount /mnt/share && mount -a.

Useful export options

  • rw or ro: read-write or read-only.
  • sync: the server confirms writes only after they are on disk. Safer than async, which is faster but can lose data if the server crashes.
  • root_squash (default): root on the client becomes nobody on the server. no_root_squash removes this protection; use it only for trusted clients such as a backup server.
  • all_squash with anonuid= and anongid=: map every client user to one server user, useful for shared upload folders.

Check and troubleshoot

  • On the server, exportfs -v shows the active exports and options.
  • On the client, nfsstat -m shows mounted shares and the NFS version in use.
  • "access denied by server while mounting": see how to fix mount.nfs: access denied by server.
  • Files owned by nobody or wrong users: user IDs differ between the machines. Use the same UID and GID for shared users on all servers.

Official documentation: Deploying an NFS server (Red Hat) and exports manual page.

Ucartz services for this topic

Was this answer helpful? 0 Users Found This Useful (0 Votes)