6.5.1

Table Of Contents
Verify Firewall Ports for NFS Clients
To enable access to NFS storage, ESXi automatically opens firewall ports for the NFS clients when you
mount an NFS datastore. For troubleshooting reasons, you might need to verify that the ports are open.
Procedure
1 Browse to the host in the vSphere Web Client navigator.
2 Click the Configure tab.
3 Under System, click Security Profile, and click Edit.
4 Scroll down to an appropriate version of NFS to make sure that the port is opened.
Using Layer 3 Routed Connections to Access NFS Storage
When you use Layer 3 (L3) routed connections to access NFS storage, consider certain requirements
and restrictions.
Ensure that your environment meets the following requirements:
n
Use Cisco's Hot Standby Router Protocol (HSRP) in IP Router. If you are using a non-Cisco router,
use Virtual Router Redundancy Protocol (VRRP) instead.
n
To prioritize NFS L3 traffic on networks with limited bandwidths, or on networks that experience
congestion, use Quality of Service (QoS). See your router documentation for details.
n
Follow Routed NFS L3 recommendations offered by storage vendor. Contact your storage vendor for
details.
n
Disable Network I/O Resource Management (NetIORM).
n
If you are planning to use systems with top-of-rack switches or switch-dependent I/O device
partitioning, contact your system vendor for compatibility and support.
In an L3 environment, the following restrictions apply:
n
The environment does not support VMware Site Recovery Manager.
n
The environment supports only the NFS protocol. Do not use other storage protocols such as FCoE
over the same physical network.
n
The NFS traffic in this environment does not support IPv6.
n
The NFS traffic in this environment can be routed only over a LAN. Other environments such as WAN
are not supported.
Using Kerberos for NFS 4.1
With NFS version 4.1, ESXi supports the Kerberos authentication mechanism.
The RPCSEC_GSS Kerberos mechanism is an authentication service. It allows an NFS 4.1 client
installed on ESXi to prove its identity to an NFS server before mounting an NFS share. The Kerberos
security uses cryptography to work across an insecure network connection.
vSphere Storage
VMware, Inc. 172