6.5.1

Table Of Contents
n
ESXi supports Layer 2 and Layer 3 Network switches. If you use Layer 3 switches, ESXi hosts and
NFS storage arrays must be on different subnets and the network switch must handle the routing
information.
n
Configure a VMkernel port group for NFS storage. You can create the VMkernel port group for IP
storage on an existing virtual switch (vSwitch) or on a new vSwitch. The vSwitch can be a vSphere
Standard Switch (VSS) or a vSphere Distributed Switch (VDS).
n
If you use multiple ports for NFS traffic, make sure that you correctly configure your virtual switches
and physical switches.
n
NFS 3 and NFS 4.1 support IPv6.
NFS File Locking
File locking mechanisms are used to restrict access to data stored on a server to only one user or
process at a time. NFS 3 and NFS 4.1 use incompatible file locking mechanisms.
NFS 3 locking on ESXi does not use the Network Lock Manager (NLM) protocol. Instead, VMware
provides its own locking protocol. NFS 3 locks are implemented by creating lock files on the NFS server.
Lock files are named .lck-file_id..
NFS 4.1 uses share reservations as a locking mechanism.
Because NFS 3 and NFS 4.1 clients do not use the same locking protocol, you cannot use different NFS
versions to mount the same datastore on multiple hosts. Accessing the same virtual disks from two
incompatible clients might result in incorrect behavior and cause data corruption.
NFS Security
With NFS 3 and NFS 4.1, ESXi supports the AUTH_SYS security. In addition, for NFS 4.1, the Kerberos
security mechanism is supported.
NFS 3 supports the AUTH_SYS security mechanism. With this mechanism, storage traffic is transmitted
in an unencrypted format across the LAN. Because of this limited security, use NFS storage on trusted
networks only and isolate the traffic on separate physical switches. You can also use a private VLAN.
NFS 4.1 supports the Kerberos authentication protocol to secure communications with the NFS server.
Nonroot users can access files when Kerberos is used. For more information, see Using Kerberos for
NFS 4.1.
In addition to Kerberos, NFS 4.1 supports traditional non-Kerberos mounts with the AUTH_SYS security.
In this case, use root access guidelines for NFS version 3.
Note You cannot use two security mechanisms, AUTH_SYS and Kerberos, for the same NFS 4.1
datastore shared by multiple hosts.
NFS Multipathing
While NFS 3 with ESXi does not provide multipathing support, NFS 4.1 supports multiple paths.
vSphere Storage
VMware, Inc. 169