在Windows的VMWare中禁用CentOS7虚拟机互联网并保留本地网络访问
Alright, let's fix this properly—instead of messing with your host's internet (which caused the VM freeze), we can configure the CentOS 7 VM itself to block direct internet access while keeping local network connectivity and allowing traffic through your local proxy. Here are the most reliable methods:
Method 1: Use iptables to Block Internet (Persistent Rules)
This method gives you granular control over which traffic is allowed. It avoids freezing the VM because we're only modifying the VM's own network rules, not the host's.
Step 1: Allow Critical Local & Loopback Traffic
First, ensure the VM can communicate with itself and the local subnet (replace 192.168.1.0/24 with your actual local network range):
# Allow loopback (prevents system freezes from broken internal communication) iptables -A INPUT -i lo -j ACCEPT iptables -A OUTPUT -o lo -j ACCEPT # Allow all traffic to/from the local subnet iptables -A INPUT -s 192.168.1.0/24 -j ACCEPT iptables -A OUTPUT -d 192.168.1.0/24 -j ACCEPT
Step 2: Allow Traffic to Your Local Proxy
Replace 192.168.1.100 and 8080 with your proxy's IP and port:
iptables -A OUTPUT -d 192.168.1.100 -p tcp --dport 8080 -j ACCEPT
Step 3: Block All Other Outgoing Internet Traffic
# Allow established/related connections (so existing local sessions don't break) iptables -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT # Drop all other outgoing traffic iptables -A OUTPUT -j DROP
Step 4: Save Rules to Persist After Reboot
# Save rules to the default iptables config file iptables-save > /etc/sysconfig/iptables # Restart iptables to apply changes systemctl restart iptables
Method 2: Remove Default Gateway + Configure System-Wide Proxy
This is simpler if you just need to block direct internet access entirely. Without a default gateway, the VM can't reach external networks, but can still access local devices.
Step 1: Remove Default Gateway (Temporary & Permanent)
First, check your current routes:
ip route show
Remove the default gateway temporarily:
ip route del default
To make this permanent, edit your network interface config file (replace eth0 with your interface name, e.g., ens33):
vi /etc/sysconfig/network-scripts/ifcfg-eth0
Comment out or delete the GATEWAY line, then restart the network service:
systemctl restart network
Step 2: Configure System-Wide Proxy Settings
Create a proxy config file for all users:
vi /etc/profile.d/proxy.sh
Add these lines (replace with your proxy details):
export http_proxy=http://192.168.1.100:8080/ export https_proxy=http://192.168.1.100:8080/ export no_proxy=localhost,127.0.0.1,192.168.1.0/24
Apply the settings immediately:
source /etc/profile.d/proxy.sh
Step 3: Configure Proxy for Yum (If Needed)
Edit /etc/yum.conf to add proxy support for package management:
vi /etc/yum.conf
Add this line at the end:
proxy=http://192.168.1.100:8080/
Troubleshooting & Verification
- Test local connectivity:
ping 192.168.1.100(your proxy or another local machine) should work. - Test internet block:
ping 8.8.8.8should fail. - Test proxy access:
curl -x http://192.168.1.100:8080 http://example.comshould return the webpage content.
内容的提问来源于stack exchange,提问作者Jonathan McDevitt

