Red Hat Training
A Red Hat training course is available for Red Hat Enterprise Linux
48.2.4. Securing NFS
The Network File System (NFS) is a service that provides network accessible file systems for client machines. Refer to Chapter 21, Network File System (NFS) for more information about NFS. The following subsections assume a basic knowledge of NFS.
The version of NFS included in Red Hat Enterprise Linux, NFSv4, no longer requires the
portmapservice as outlined in Section 48.2.2, “Securing Portmap”. NFS traffic now utilizes TCP in all versions, rather than UDP, and requires it when using NFSv4. NFSv4 now includes Kerberos user and group authentication, as part of the
RPCSEC_GSSkernel module. Information on
portmapis still included, since Red Hat Enterprise Linux supports NFSv2 and NFSv3, both of which utilize
22.214.171.124. Carefully Plan the Network
Now that NFSv4 has the ability to pass all information encrypted using Kerberos over a network, it is important that the service be configured correctly if it is behind a firewall or on a segmented network. NFSv2 and NFSv3 still pass data insecurely, and this should be taken into consideration. Careful network design in all of these regards can help prevent security breaches.