nfs服务端部署关键卡点是rpcbind启动顺序、/etc/exports语法校验和防火墙端口放行;任一出错均导致showmount -e失败,需按序启动rpcbind与nfs-server、严格检查exports路径/ip/括号/空格,并开放2049及111等必要端口。

NFS服务端在Linux上不是“装完就能用”,关键卡点在rpcbind启动顺序、/etc/exports语法校验、以及防火墙放行端口——三者任一出错,showmount -e都会失败。
安装NFS服务端包前先确认发行版命令差异
Debian/Ubuntu用nfs-kernel-server,CentOS/RHEL 7用nfs-utils,RHEL 8+改用dnf install nfs-utils。别混用:apt install nfs-utils在Ubuntu上会装错包,不提供exportfs等核心命令。
装完必须同时装nfs-common(客户端工具),否则showmount命令不存在,连本地验证都做不了。
- Ubuntu/Debian:
sudo apt update && sudo apt install -y nfs-kernel-server nfs-common - CentOS 7:
sudo yum install -y nfs-utils - RHEL 8+/AlmaLinux 9:
sudo dnf install -y nfs-utils
配置/etc/exports时最常踩的四个坑
文件路径、IP写法、括号、空格——任意一个字符错,exportfs -r就静默失败,systemctl status nfs-server也看不出问题。
- 共享路径必须是绝对路径,且目录已存在(
mkdir -p /srv/nfs/share后记得chown nobody:nogroup) - 客户端地址不能写
*就完事:内网建议写192.168.1.0/24,单机测试用localhost更安全 - 权限选项括号
()必须紧贴IP,中间不能有空格:/srv/nfs/share 192.168.1.10(rw,sync)✅,192.168.1.10 (rw,sync)❌ - 改完文件必须运行
sudo exportfs -r重载,不是重启服务;漏这步,showmount -e localhost一定返回空
showmount -e报clnt_create: RPC: Program not registered怎么办
这是rpcbind和nfs-server服务启动顺序错了,尤其在systemd新版本中常见。不能只systemctl restart nfs-server。
- 先停两个服务:
sudo systemctl stop nfs-server rpcbind - 再按顺序启动:
sudo systemctl start rpcbind && sudo systemctl start nfs-server - 验证是否注册成功:
rpcinfo -p localhost | grep nfs,能看到nfs对应程序号才正常 - 如果仍失败,检查
systemctl list-dependencies nfs-server,确认rpcbind确实在依赖链里
防火墙没开对端口,挂载时会卡住或报No route to host
NFS不是只开2049端口就行。v4默认走2049,但v3及以下依赖rpcbind动态分配端口,必须放行整个rpc-bind服务或指定端口范围。
- 推荐做法(Ubuntu UFW):
sudo ufw allow from 192.168.1.0/24 to any port 2049 proto tcp+sudo ufw allow from 192.168.1.0/24 to any port 111 proto tcp - CentOS firewalld:
sudo firewall-cmd --permanent --add-service=nfs+--add-service=rpc-bind+--add-service=mountd,然后reload - 临时关防火墙测试可以,但上线前必须配端口策略——否则
mount命令会超时卡死,无明确错误提示
真正麻烦的从来不是“怎么配”,而是showmount没输出时你不知道该查rpcinfo、exportfs -v还是journalctl -u nfs-server。多打两行诊断命令,比反复重启服务快得多。











