Skip to main content

Port Details

Port
2049
Transport
TCP / UDP
Service
NFS
IANA service name
nfs, shilp
Range
User port (1024-49151)

Security Exposure

Exported file systems reachable from untrusted networks can disclose or allow modification of stored data. On Linux the default export security flavor, sec=sys, provides no cryptographic security, so the server trusts the user and group IDs the client presents. RFC 7530 requires implementations to support RPCSEC_GSS but leaves its deployment optional.

Hardening

  • +Restrict TCP and UDP 2049 to the client subnets that mount the exports and block them at the perimeter.
  • +List explicit client hosts in /etc/exports instead of wildcards, and export read-only where writes are not needed.
  • +Keep root_squash enabled so requests from uid 0 on clients map to the anonymous user.
  • +Use Kerberos security flavors (sec=krb5i or krb5p) or RPC-with-TLS (xprtsec=) to protect exports that carry sensitive data.

Monitoring

Track which clients mount each export and alert on mounts from hosts outside the expected list. Watch for new NFS listeners on 2049 on hosts that are not file servers.

Tools for Auditing and Monitoring NFS

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Wireshark

Open Source
Network Monitoring Tools

Network packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.

LicenseGPL-2.0-or-later
PlatformWindows, macOS, Linux, BSD

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Frequently Asked Questions

Is NFS port 2049 TCP or UDP?→

IANA lists 2049 for TCP, UDP and SCTP. RFC 7530 requires NFSv4 implementations to support TCP and to run over a transport with congestion control.

What does root_squash do?→

root_squash maps requests from uid and gid 0 on the client to the anonymous uid and gid on the server. It does not protect other sensitive accounts.

Can NFS traffic be encrypted?→

Yes. Linux supports the krb5p security flavor for privacy protection and RPC-with-TLS (RFC 9289) through the xprtsec= export option.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 2049 is not guaranteed to be NFS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).