Use the protocol native to the clients. SMB is the file sharing protocol of Windows, works well from macOS and Linux, and authenticates each user against the directory. NFS is the native protocol of Linux and Unix, and the usual choice for Linux servers, hypervisor datastores and application storage.
CIFS is an old SMB dialect, not a third option, and SMB1 should be switched off. SMB checks who the user is, while NFS with AUTH_SYS trusts the client.
- Windows and mixed office desktops: SMB
- Linux servers, containers and hypervisor storage: NFS
- CIFS is an early SMB dialect. Say SMB and use version 3
- SMB1 is deprecated and should be off everywhere
- NFS with default AUTH_SYS trusts the client's claimed user ID
On this page
NFSWhat NFS is
NFS, the Network File System, is a protocol that lets a client mount a directory from a remote server and use it as if it were a local file system. It came out of the Unix world, and it is built into every Linux distribution and most storage appliances.
The current major version is NFSv4, with NFSv3 still common.
An NFS server exports directories to clients, usually named by host or subnet. The client mounts the export at a path such as /mnt/data, and applications read and write files there with ordinary file operations. Permissions follow the Unix model of user IDs, group IDs and mode bits, with NFSv4 adding richer access control lists.
NFS is common in places where no person opens files by hand: Linux application servers sharing a data directory, home directories on Linux workstations, container platforms, backup targets and hypervisor datastores. VMware ESXi, for example, can mount an NFS export as a datastore for virtual machines.
SMB and CIFSWhat SMB is, and where CIFS fits
SMB, Server Message Block, is the file and printer sharing protocol of Windows. When someone maps a drive letter to a network share, opens a path such as \\server\share in File Explorer or saves to a folder on a NAS from a Windows PC, that traffic is SMB. It runs over TCP port 445.
SMB has gone through several versions, which Microsoft calls dialects. The client and server negotiate the highest dialect both support. Current systems use SMB 3.x, which adds encryption, better performance over WAN links and features for server workloads, such as storing Hyper-V virtual machines on file shares.
CIFS, the Common Internet File System, is an early dialect of SMB from the 1990s. The CIFS vs SMB question therefore has a short answer: CIFS is old SMB.
Many NAS menus and Linux mount types still say CIFS, which is a naming habit, not a sign of the old protocol. The Linux cifs mount type, for example, negotiates the highest SMB 2 or later version both ends support unless told otherwise.
The oldest dialect, SMB1, is the one that matters for security. Microsoft's documentation says SMBv1 has not been installed by default since Windows 10 version 1709, and that Microsoft publicly deprecated it in 2014. It lacks the protections of later versions and was the protocol exploited by WannaCry.
Leave it off, and replace any device that still needs it.
Which to useNFS vs SMB: choose the protocol your clients speak
The NFS vs SMB decision is rarely about which protocol is better in the abstract. It is about which clients will use the share. Both protocols can serve files well. Each is at its best, and simplest to secure, on its native platform.
Windows desktops and laptops. SMB. It is built in, integrates with Active Directory permissions, handles Windows file locking and offline files, and needs nothing installed. Windows can mount NFS with an optional client component, but user mapping and permissions become awkward.
Mac clients. SMB, which macOS connects to natively. NFS works from a Mac as well, but mixed offices standardize on SMB.
Linux servers and applications. NFS, which is native, simple to mount in /etc/fstab and has Unix permissions that match the servers. SMB works from Linux through the cifs client and is the better choice when the same share also serves Windows users.
Hypervisors and containers. NFS for datastores and persistent volumes on VMware and Linux platforms. SMB 3 for Hyper-V, which stores virtual machines on SMB shares, not NFS.
A mixed office. SMB for the people, NFS for the servers, often from the same NAS. Most NAS systems and file servers can serve one folder over both protocols, but mixing them on the same data complicates permissions, so keep it for cases that need it.
Windows Server includes Server for NFS and Client for NFS components when you need both from one file server.
SecurityAuthentication is the real difference
The most important difference between NFS and SMB is not speed. It is how the server decides who is making a request.
SMB authenticates the user. Every connection is tied to a user account. In an Active Directory domain, Windows uses Kerberos to prove the user's identity to the file server, and the server applies that user's NTFS permissions. A stolen laptop on the network does not get access to a share without a valid account.
NFS with AUTH_SYS trusts the client. The default NFS security flavor, AUTH_SYS, sends the user ID and group IDs that the client machine claims. The server checks only that the request came from an allowed host.
RFC 5531, which defines the RPC system NFS runs on, says AUTH_SYS is known to be insecure due to the lack of a verifier to validate the credential.
In practice, anyone with root on an allowed client machine can act as any user ID on the export. That is acceptable for a locked down server network where only trusted machines are allowed, and not acceptable for exports reachable from desktops or guest networks.
NFS with Kerberos authenticates the user. NFS supports Kerberos through the sec mount option. The Linux nfs man page describes three flavors: krb5 proves the user's identity on each request, krb5i adds an integrity check, and krb5p encrypts every request.
It requires a Kerberos realm, keytabs on each client and matching identities, which is why many small environments never set it up.
PerformanceSMB vs NFS performance
Published SMB vs NFS performance comparisons are full of benchmarks, and most of them measure a particular NAS, a particular client and a particular file mix. The protocol is rarely the bottleneck in an office. The disks, the network link and the configuration usually are.
A few differences hold generally, without numbers.
Many small files. Workloads that open, check and close thousands of small files, such as source code trees and some applications, are sensitive to round trips. Client caching settings and protocol version matter more here than the protocol name.
Large sequential files. Backups, video and virtual disk files tend to reach the limit of the disks or the link with either protocol when both are configured properly.
Encryption and signing. SMB signing and SMB encryption, and NFS krb5i and krb5p, cost CPU on both ends. Microsoft notes that SMB encryption does not cover data at rest, only in transit.
Multichannel and RDMA. SMB 3 can use several network links at once and RDMA network cards. NFS has its own options for the same goals. Both matter only on server grade hardware.
If a share feels slow, check the link speed, the disk activity on the NAS and the protocol version in use before changing protocol. The page on NAS vs SAN covers when file level storage stops being the right design at all.
PitfallsWhere people go wrong
Leaving SMB1 on for one old device. A scanner or NAS that needs SMB1 keeps a deprecated protocol alive for the whole network. Update its firmware or replace it.
Exporting NFS to whole subnets with AUTH_SYS. An export open to the office subnet is open to anyone who can plug in a Linux laptop and claim a user ID. Limit exports to named server addresses, or use Kerberos.
Using no_root_squash without a reason. By default NFS maps the client's root user to an unprivileged user. Turning that off gives root on any allowed client root on the export.
Exposing SMB to the internet. Port 445 should never be reachable from outside. Remote users get to file shares over a VPN or through a cloud file service.
Serving the same folder over both protocols by default. It works, but permissions and file locking behave differently for each side. Do it only for data that really needs both.
Blaming the protocol for a slow share. A 100 megabit link, a failing disk or an SMB signing setting on a weak NAS is more likely than NFS or SMB itself. See the guide on sizing shared storage before replacing hardware.
ComparisonNFS and SMB side by side, and which clients each one suits
| Criterion | NFS | SMB |
|---|---|---|
| Native platform | Linux and Unix | Windows |
| macOS support | Yes | Yes, the usual choice |
| Default authentication | AUTH_SYS, trusts the client | Per user account |
| Strong authentication | Kerberos, extra setup | Kerberos, built in with a domain |
| Encryption in transit | Kerberos krb5p | SMB 3 encryption, per share or server |
| Permissions model | Unix IDs and mode bits, NFSv4 ACLs | NTFS ACLs |
| Typical use | Linux servers, datastores, containers | Office file shares, Windows servers, Hyper-V |
| Port | 2049 | 445 |
For an office where people open files from their desks, SMB wins on nearly every row that matters: per user authentication, integration with the directory and support on every desktop. NFS wins where the clients are Linux machines and the security boundary is the server network itself.
FAQFrequently asked questions
What is NFS?
NFS, the Network File System, is a protocol that lets a computer mount a directory from a remote server over the network and use it like a local folder. It is native to Linux and Unix and common for servers, datastores and containers.
NFS or SMB: which should I use?
Use the protocol your clients speak natively. Choose SMB for Windows and Mac desktops and anything tied to Active Directory permissions. Choose NFS for Linux servers, containers and hypervisor datastores on a trusted server network.
Is SMB faster than NFS?
Not as a rule. Published benchmarks vary with the hardware, client, protocol version and file mix. In most offices the disks, the network link and the configuration limit speed long before the choice between NFS and SMB does.
What is the difference between NFS and CIFS?
CIFS is an early dialect of SMB, so NFS vs CIFS is really NFS vs SMB. NFS comes from Unix and Linux, while CIFS and SMB come from Windows. Modern systems should use SMB 3, even where menus still say CIFS.
Is CIFS the same as SMB?
CIFS is one early version, or dialect, of SMB. The term is still used in NAS menus and the Linux cifs mount type, which today speak modern SMB. The old CIFS and SMB1 dialects themselves should not be used.
Should SMB1 be disabled?
Yes. Microsoft deprecated SMBv1 in 2014 and has not installed it by default since Windows 10 version 1709. It lacks the security of later versions. Any device that still requires SMB1 should get a firmware update or be replaced.
Is NFS secure?
It can be. NFS with Kerberos authenticates each user and can encrypt traffic with krb5p. NFS with the default AUTH_SYS trusts the user IDs the client sends, so it is only acceptable on a trusted server network with exports limited to specific hosts.
Does SMB encrypt data?
SMB 3 supports end to end encryption in transit, configurable per share or for the whole server. It does not encrypt data at rest on the server's disks, which needs disk encryption such as BitLocker. SMB signing protects integrity without encrypting.
Can Windows use NFS?
Yes. Windows can install an optional Client for NFS, and Windows Server includes Server for NFS. For desktops SMB is simpler, because NFS on Windows needs user ID mapping to line up permissions between the two systems.
Can Linux use SMB?
Yes. Linux mounts SMB shares with the cifs client and can serve SMB with Samba. It is the right choice when a share must also serve Windows users. For Linux only workloads, NFS is usually simpler.
Which ports do NFS and SMB use?
SMB uses TCP port 445. NFSv4 uses port 2049. NFSv3 also needs portmapper on port 111 and several helper services, which makes it harder to pass through a firewall than NFSv4.
Should I use NFS or SMB for VMware or Hyper-V?
VMware ESXi supports NFS datastores, so NFS is a common choice there. Hyper-V stores virtual machines on SMB 3 shares, not NFS. Use the protocol the hypervisor supports natively for virtual machine storage.
Keep readingRelated concepts
Read next · Directory and identity Active Directory Explained The directory that gives SMB its per user authentication and share permissions. Open this next15 min- Shared storage · 12 min NAS vs SAN File level NAS and block level SAN compared, and when a file share stops being the right design.
- Ports · 10 min SMB Port 445, and the One Rule That Matters About It What runs on TCP port 445, and how to keep SMB off the internet.