Comprehensive Guide to Samba and NFS File Sharing
Samba enables seamless file sharing between Linux, Windows, and macOS systems, while NFS provides efficient native file sharing for Unix-based systems. This guide covers both services with security best practices and optimal configurations.
Samba Configuration
Section titled “Samba Configuration”Base Configuration File
sudo nano /etc/samba/smb.conf
[global]# Basic server settingsworkgroup = WORKGROUPserver role = standalone serverlog file = /var/log/samba/log.%mmax log size = 1000logging = file
# Security settingsmap to guest = neverunix password sync = yespasswd program = /usr/bin/passwd %upam password change = yesobey pam restrictions = yes
# Network configurationinterfaces = 127.0.0.1 eth0bind interfaces only = yesclient min protocol = SMB2server max protocol = SMB3
# Performance optimizationsaio read size = 16384aio write size = 16384
# macOS compatibilityvfs objects = catia fruit streams_xattrfruit:metadata = streamfruit:encoding = nativefruit:locking = nonefruit:resource = filefruit:posix_rename = yesfruit:zero_file_id = yeshide files = /.DS_Store/
# Example share configuration[share_name]path = /path/to/sharewritable = yesbrowseable = yesforce create mode = 0660force directory mode = 0770valid users = @groupinherit permissions = yesShare Mount Configuration
Section titled “Share Mount Configuration”Secure Credentials Setup
# Create credentials filesudo nano /root/.smbcredentials
username=your_usernamepassword=your_password
# Secure the filesudo chmod 600 /root/.smbcredentialsMount Entry (/etc/fstab)
# Format: //server/share /mount/point cifs options//server/share /mnt/share cifs credentials=/root/.smbcredentials,uid=1000,gid=1000,iocharset=utf8,vers=3.0 0 0NFS Configuration
Section titled “NFS Configuration”Server Setup
# Edit exports filesudo nano /etc/exports
# Secure share configuration with specific subnet/shared/directory 192.168.1.0/24(rw,sync,no_subtree_check,no_root_squash)Client Mount Configuration
# Create mount pointsudo mkdir -p /mnt/nfs_share
# Add to /etc/fstabserver:/shared/directory /mnt/nfs_share nfs defaults,_netdev,noatime,rsize=8192,wsize=8192 0 0Service Management
Section titled “Service Management”Samba Commands
# Verify configurationtestparm
# Manage servicessudo systemctl restart smbd nmbdsudo systemctl status smbd
# Test mount pointssudo mount -aNFS Commands
# Export sharessudo exportfs -a
# Verify exportssudo exportfs -v
# Restart NFS serversudo systemctl restart nfs-kernel-serverSecurity Best Practices
Section titled “Security Best Practices”- Use SMB3 protocol for enhanced security
- Implement user-based access control
- Restrict share access to specific networks
- Regular security audits
- Keep services updated
- Use strong passwords
- Implement proper file permissions
Prerequisites
Section titled “Prerequisites”- Root or sudo access
- Required packages:
Terminal window # For Sambasudo apt install samba samba-common-bin# For NFSsudo apt install nfs-kernel-server nfs-common - Proper network configuration
- Firewall rules for ports:
- Samba: 445/tcp
- NFS: 2049/tcp
Troubleshooting Tips
Section titled “Troubleshooting Tips”- Check service status with
systemctl status - View logs:
/var/log/samba/for Samba,/var/log/syslogfor NFS - Test network connectivity with
pingandtelnet - Verify permissions on shared directories
- Use
smbclient -L //serverto list Samba shares