NFS client setup¶
This page covers installing the NFS client utilities, mounting remote exports manually and persistently, configuring autofs for on-demand mounting, and setting up NFSv4 ID mapping. It assumes an NFS server is already running -- see Server setup if not.
Install packages¶
After installation, ensure rpcbind is running (required for NFSv2/v3 mounts):
NFSv4 does not require rpcbind
If you mount exclusively with vers=4, rpcbind is not needed on the client. The NFS client connects directly to port 2049 without portmapper lookups.
Manual mount¶
This uses the system default NFS version (typically v4 on modern kernels, falling back to v3). To force a specific version:
sudo mount -t nfs -o vers=3 192.168.1.10:/srv/nfs/shared /mnt # NFSv3
sudo mount -t nfs -o vers=4 192.168.1.10:/srv/nfs/shared /mnt # NFSv4
Verify before mounting
Persistent mounts with /etc/fstab¶
To mount automatically at boot, add a line to /etc/fstab:
Create the mount point and test:
The _netdev option delays the mount until the network is up. Always use it for NFS entries in fstab.
Common fstab configurations
Autofs configuration¶
autofs mounts NFS exports on demand when a user accesses the mount point, and unmounts them after an idle timeout.
Add an entry to /etc/auto.master:
Create the map file:
shared -fstype=nfs,rw,hard,_netdev 192.168.1.10:/srv/nfs/shared
backups -fstype=nfs,ro,hard,_netdev 192.168.1.10:/srv/nfs/backups
Enable and test:
Verify the mount¶
df -hT | grep nfs # mounted NFS filesystems
findmnt -t nfs,nfs4 # detailed mount information with options
NFSv4 ID mapping¶
NFSv4 transmits file ownership as user@domain strings instead of raw UID/GID integers. The idmapd daemon translates between these strings and local UIDs/GIDs. If ID mapping is misconfigured, all files appear owned by nobody:nogroup.
Edit /etc/idmapd.conf on both client and server:
[General]
Domain = example.com
[Mapping]
Nobody-User = nobody
Nobody-Group = nogroup
Domain must match
The Domain value must be identical on client and server. A mismatch causes all file ownership to map to nobody. This is the most common cause of ownership display issues on NFSv4 mounts.
Restart idmapd after editing:
Common mount options¶
| Option | Default | Description |
|---|---|---|
vers=N |
Auto | Force NFS version (2, 3, 4, 4.1, 4.2) |
sec=MODE |
sys |
Auth flavor: sys, krb5, krb5i, krb5p |
hard |
Yes | Retry indefinitely on server failure (prevents data loss, can hang) |
soft |
No | Return errors after retrans retries (prevents hangs, risks corruption) |
timeo=N |
600 | RPC timeout in tenths of a second |
retrans=N |
2 | Retries before soft-mount error or hard-mount warning |
_netdev |
No | Delay mount until network is up (always use in fstab) |
nosuid |
No | Ignore setuid/setgid bits (F-4.2) |
nodev |
No | Ignore device nodes (F-4.3) |
noexec |
No | Prevent binary execution |
proto=tcp |
TCP | Transport protocol (UDP also supported for v2/v3) |
Minimum security options for untrusted exports
When mounting an export you do not control, always add nosuid,nodev,noexec:
This prevents three classes of privilege escalation via crafted files on the remote export. See F-7.4.
Next steps¶
- /etc/exports syntax -- understand server-side export definitions
- Export options reference -- server-side options with security implications
- Hardening checklist -- secure both client and server
- Kerberos authentication -- replace AUTH_SYS with cryptographic authentication