# Account for NFSv3 ancillary services in NetApp firewall testing

> Why is allowing only the NFS port insufficient to validate an Azure NetApp Files NFSv3 path?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-547-account-for-nfsv3-ancillary-services-in-netapp-firewall-testing/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:49+00:00
- Modified: 2026-09-10T02:11:19+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Why is allowing only the NFS port insufficient to validate an Azure NetApp Files NFSv3 path?

## Potentially affected

Apply this review to the actual NFS version selected for the Azure NetApp Files volume. This is a connectivity contract, not a recommendation to change protocol versions solely to simplify a firewall rule.

## DSE recommendation

Make the required NFSv3 service paths explicit before accepting a firewall change.

## Article

## Source facts

For Azure NetApp Files, NFSv3 uses separate services for port discovery, mounting, locking, status and quotas. Their fixed ports are 111 for Portmapper, 635 for Mount, 4045 for NLM, 4046 for NSM and 4049 for Rquota, alongside NFS on 2049. Microsoft says these port numbers cannot be changed. NFSv4 integrates locking into its protocol instead of using the ancillary locking service; Azure NetApp Files supports NFSv4.1 within that protocol family. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/azure-netapp-files/network-attached-storage-protocols).

## Applicability

Apply this review to the actual NFS version selected for the Azure NetApp Files volume. This is a connectivity contract, not a recommendation to change protocol versions solely to simplify a firewall rule.

## DSE recommendation

Make the required NFSv3 service paths explicit before accepting a firewall change. Ask the storage, client and network owners to agree which operations the workload needs and where the corresponding traffic must pass. Keep the permitted client population and destination volume alongside the port list. Avoid expanding access to unrelated networks when one operation fails; first identify which service and path produced the failure.

## Verification

Use an approved client to check discovery, mounting and representative file activity through the intended controls. Include a locking exercise appropriate to the application instead of relying on a basic connection to port 2049. Compare observations with the agreed service matrix and confirm an excluded client remains excluded. Record the negotiated NFS version so results cannot be misapplied to a different protocol configuration.

## Official references

[Microsoft Learn: Understand NAS protocols in Azure NetApp Files](https://learn.microsoft.com/en-us/azure/azure-netapp-files/network-attached-storage-protocols).

## Primary reference

- Name: Understand NAS protocols in Azure NetApp Files | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/azure-netapp-files/network-attached-storage-protocols
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Account for NFSv3 ancillary services in NetApp firewall testing,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-547-account-for-nfsv3-ancillary-services-in-netapp-firewall-testing/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
