Port 2049: Network File System
Port 2049 is the registered port for NFS, and RFC 7530 states that it SHOULD be the default for NFSv4 servers, as it was for NFSv2 and NFSv3. NFS shares directories from Linux and Unix file servers and NAS appliances to client machines. IANA also lists an unrelated name, shilp, on 2049.
Port Details
Security Exposure
Exported file systems reachable from untrusted networks can disclose or allow modification of stored data. On Linux the default export security flavor, sec=sys, provides no cryptographic security, so the server trusts the user and group IDs the client presents. RFC 7530 requires implementations to support RPCSEC_GSS but leaves its deployment optional.
Hardening
- +Restrict TCP and UDP 2049 to the client subnets that mount the exports and block them at the perimeter.
- +List explicit client hosts in /etc/exports instead of wildcards, and export read-only where writes are not needed.
- +Keep root_squash enabled so requests from uid 0 on clients map to the anonymous user.
- +Use Kerberos security flavors (sec=krb5i or krb5p) or RPC-with-TLS (xprtsec=) to protect exports that carry sensitive data.
Monitoring
Track which clients mount each export and alert on mounts from hosts outside the expected list. Watch for new NFS listeners on 2049 on hosts that are not file servers.
Tools for Auditing and Monitoring NFS
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Wireshark
Open SourceNetwork packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Related Tool Categories
Frequently Asked Questions
Is NFS port 2049 TCP or UDP?→
IANA lists 2049 for TCP, UDP and SCTP. RFC 7530 requires NFSv4 implementations to support TCP and to run over a transport with congestion control.
What does root_squash do?→
root_squash maps requests from uid and gid 0 on the client to the anonymous uid and gid on the server. It does not protect other sensitive accounts.
Can NFS traffic be encrypted?→
Yes. Linux supports the krb5p security flavor for privacy protection and RPC-with-TLS (RFC 9289) through the xprtsec= export option.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 2049 is not guaranteed to be NFS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).