The NFS functionality operates as follows:
To ensure smooth NFS operations, make sure that the necessary ports for the mount process and data traffic are allowed in the firewall and VPC Security Group.
Our documentation advises that to facilitate NFS communication, it is recommended to open up the security group for the entire VPC CIDR. You can find detailed instructions on creating transit gateway attachments, configuring routing, and setting up security groups in the provided link FSx-guide
Additionally, AWS documentation provides information about the required ports for NFS communication. You can refer to the following link for further insights on creating security groups to manage access: AmazonFsx-Guide