CentOS7 configures firewalld to share the network with internal LAN machines using the NAT method
A centos7 system has two NIC, one connected to the external network segment 10.8.20.0/24, and the other connected to the internal network segment 172.168.10.0/24. Its IP is: 172.168.10.1. Other machines in the local area network can only connect to the 172.168.10.0/24 network segment. For example, the IP of one of them is: 172.168.1.100. Now to enable other machines in the local area network to connect to the external network, you can do the following on this centos7 system:
Turn on NAT forwarding
# firewall-cmd --permanent --zone=public --add-masquerade
Open port 53 used by DNS, otherwise it may cause the intranet server to be unable to perform domain name resolution although the correct DNS is set.
# firewall-cmd --zone=public --add-port=53/tcp --permanent
Restart firewall
# systemctl restart firewalld.service
In this way, on other machines in the local area network, set their IP to 172.168.10.0/24 network segment, and the default gateway to 172.168.10.1, and you can connect to the external network