OpenVPN connects, cannot route to Internet, SMB not working to internal servers, Intranet works

209 views
Skip to first unread message

kho...@gmail.com

unread,
Dec 22, 2017, 12:08:24 PM12/22/17
to tunnelblick-discuss
Thank you for taking my post. Any suggestions to resolve this would be greatly appreciated.

We are running OpenVPN and it is working great for our Windows clients. We recently added a single MAC client. This client is using TunnelBlick and we are having some trouble with VPN functionality. The client connects fine but there seems to be a routing issue. We have an Intranet on the 172.x.x.x network that the MAC client can reach when connected to the VPN. But the client cannot access the Internet nor can the client access internal resources which are subnets of 172.x.x.x.


The routing table when connected to OpenVPN is as such:

Internet:

Destination        Gateway            Flags        Refs      Use   Netif Expire

default            10.100.255.254     UGSc           14        0     en0

10.100/16          link#5             UCS             1        0     en0

10.100.22.80/32    link#5             UCS             0        0     en0

10.100.255.254/32  link#5             UCS             1        0     en0

10.100.255.254     0:50:56:b0:55:78   UHLWIir        16      264     en0   1197

127                127.0.0.1          UCS             0        0     lo0

127.0.0.1          127.0.0.1          UH              2    25261     lo0

169.254            link#5             UCS             0        0     en0

224.0.0/4          link#5             UmCS            1        0     en0

224.0.0.251        1:0:5e:0:0:fb      UHmLWI          0        0     en0

255.255.255.255/32 link#5             UCS             0        0     en0



The routing table when not connected to OpenVPN:


Internet:

Destination        Gateway            Flags        Refs      Use   Netif Expire

default            172.18.208.1       UGSc            5        0     en5

default            10.100.255.254     UGScI           0        0     en0

10.100/16          link#5             UCS             1        0     en0

10.100.22.80/32    link#5             UCS             0        0     en0

10.100.255.254/32  link#5             UCS             1        0     en0

10.100.255.254     0:50:56:b0:55:78   UHLWIir         2       16     en0    295

127                127.0.0.1          UCS             0        0     lo0

127.0.0.1          127.0.0.1          UH              2    25315     lo0

169.254            link#4             UCS             0        0     en5

169.254            link#5             UCSI            0        0     en0

172.18.208/24      link#4             UCS             1        0     en5

172.18.208.1/32    link#4             UCS             1        0     en5

172.18.208.1       0:1e:f6:e5:60:0    UHLWIir         6        0     en5   1152

172.18.208.35/32   link#4             UCS             0        0     en5

224.0.0/4          link#4             UmCS            0        0     en5

224.0.0/4          link#5             UmCSI           1        0     en0

224.0.0.251        1:0:5e:0:0:fb      UHmLWI          0        0     en0

255.255.255.255/32 link#4             UCS             0        0     en5

255.255.255.255/32 link#5             UCSI            0        0     en0





We have attempted the following troubleshooting steps:

Check the box on the TunnelBlick client GUI for "Route all IPv4 traffic through the VPN"
Check the box on the TunnelBlick client GUI for "Route all IPv4 traffic through the VPN" with the "route-delay 10" option in the config file
Added "redirect-gateway def1" to the TunnelBlick config file
Added "redirect-gateway def1" to the TunnelBlick config file with the "route-delay 10" option in the config file
Verified that the certificates are working correctly by testing on a known working system
Tested TunnelBlick on another MacBook Pro running an older version of XOS, same issue


We are running:
OpenVPN version 2.4.3
MAC OS Sierra 10.12.6
TunnelBlick version 3.7.4b



TunnelBlick diag:


Tunnelblick: OS X 10.12.6; Tunnelblick 3.7.4b (build 4921); prior version 3.7.1b (build 4813); Admin user
git commit 88763bb2b2bfcc7debb3ddc78cdf5a350722717c
 
 
Configuration ThatsUS
 
"Sanitized" condensed configuration file for /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk:
 
client
dev tun
proto udp
remote 1.1.18.125 1194
resolv-retry infinite
nobind
persist-key
persist-tun
ca ca.crt
cert client.crt
key client.key
ns-cert-type server
tls-auth ta.key 1
verb 3
explicit-exit-notify
 
 
================================================================================
 
Non-Apple kexts that are loaded:
 
Index Refs Address            Size       NAred      Name (Version) UUID <Linked Against>
  151    0 0xffffff7f85a93000 0x28000    0x28000    com.trendmicro.kext.filehook (2.2.0) B9B78439-564D-361F-AD19-E55DC3A1D28E <5 4 1>
  152    0 0xffffff7f85abb000 0xb000     0xb000     com.trendmicro.kext.KERedirect (2.2.0) 5D4EB4F5-61E7-3419-A817-E874B322672E <4 1>
  153    0 0xffffff7f85ac6000 0x4000     0x4000     com.trendmicro.kext.iTMKernAPI (1046) 976C5904-255C-3665-A9AA-62CB6316026B <4 1>
 
================================================================================
 
There are no unusual files in ThatsUS.tblk
 
================================================================================
 
Configuration preferences:
 
-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0
-lastConnectionSucceeded = 1
 
================================================================================
 
NAldcard preferences:
 
-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0
 
================================================================================
 
Program preferences:
 
inhibitOutboundTunneblickTraffic = 0
launchAtNextLogin = 1
notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0
tunnelblickVersionHistory = (
    "3.7.4b (build 4921)",
    "3.7.1b (build 4813)",
    "3.7.4b (build 4921)"
)
lastLaunchTime = 535576828.024307
lastLanguageAtLaunchWasRTL = 0
connectionNAndowDisplayCriteria = showWhenConnecting
maxLogDisplaySize = 102400
lastConnectedDisplayName = ThatsUS
keyboardShortcutIndex = 1
updateCheckAutomatically = 0
NSNAndow Frame SettingsSheetNAndow = 687 363 829 524 0 0 1680 1027
NSNAndow Frame ConnectingNAndow = 634 616 412 232 0 0 1680 1027
NSNAndow Frame SUUpdateAlert = 530 496 620 392 0 0 1680 1027
NSNAndow Frame ListingNAndow = 120 110 1680 947 0 0 1920 1057
detailsNAndowFrameVersion = 4921
detailsNAndowFrame = {{381, 440}, {920, 468}}
detailsNAndowLeftFrame = {{0, 0}, {165, 350}}
detailsNAndowVieNAndex = 0
detailsNAndowConfigurationsTabIdentifier = log
leftNavSelectedDisplayName = ThatsUS
AdvancedNAndowTabIdentifier = vpnCredentials
haveDealtNAthOldTunTapPreferences = 1
haveDealtNAthOldLoginItem = 1
SUEnableAutomaticChecks = 0
SUScheduledCheckInterval = 86400
SUSendProfileInfo = 0
SULastCheckTime = 2017-12-20 17:22:13 +0000
SUHasLaunchedBefore = 1
WebKitDefaultFontSize = 16
WebKitStandardFont = Times
askedUserIfOKToCheckThatIPAddressDidNotChangeAfterConnection = 1
haveDealtNAthSparkle1dot5b6 = 1
updateSendProfileInfo = 0
 
================================================================================
 
Tunnelblick Log:
 
*Tunnelblick: OS X 10.12.6; Tunnelblick 3.7.4b (build 4921); prior version 3.7.1b (build 4813)
2017-12-21 13:20:43 *Tunnelblick: Attempting connection NAth ThatsUS; Set nameserver = 769; monitoring connection
2017-12-21 13:20:43 *Tunnelblick: openvpnstart start ThatsUS.tblk 1338 769 0 3 0 1065264 -ptADGNWradsgnw 2.3.18-openssl-1.0.2n
2017-12-21 13:20:44 *Tunnelblick: openvpnstart log:
     OpenVPN started successfully. Command used to start OpenVPN (one argument per displayed line):
    
          /Applications/Tunnelblick.app/Contents/Resources/openvpn/openvpn-2.3.18-openssl-1.0.2n/openvpn
          --daemon
          --log
          /Library/Application Support/Tunnelblick/Logs/-SLibrary-SApplication Support-STunnelblick-SShared-SThatsUS.tblk-SContents-SResources-Sconfig.ovpn.769_0_3_0_1065264.1338.openvpn.log
          --cd
          /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk/Contents/Resources
          --setenv
          IV_GUI_VER
          "net.tunnelblick.tunnelblick 4921 3.7.4b (build 4921)"
          --verb
          3
          --config
          /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk/Contents/Resources/config.ovpn
          --verb
          3
          --cd
          /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk/Contents/Resources
          --management
          127.0.0.1
          1338
          --management-query-passwords
          --management-hold
          --script-security
          2
          --up
          /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw
          --down
          /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw
 
2017-12-21 13:20:43 OpenVPN 2.3.18 x86_64-apple-darNAn [SSL (OpenSSL)] [LZO] [PKCS11] [MH] [IPv6] built on Dec  7 2017
2017-12-21 13:20:43 library versions: OpenSSL 1.0.2n  7 Dec 2017, LZO 2.10
2017-12-21 13:20:43 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:1338
2017-12-21 13:20:43 Need hold release from management interface, waiting...
2017-12-21 13:20:43 *Tunnelblick: openvpnstart starting OpenVPN
2017-12-21 13:20:44 *Tunnelblick: Established communication NAth OpenVPN
2017-12-21 13:20:44 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:1338
2017-12-21 13:20:44 MANAGEMENT: CMD 'pid'
2017-12-21 13:20:44 MANAGEMENT: CMD 'state on'
2017-12-21 13:20:44 MANAGEMENT: CMD 'state'
2017-12-21 13:20:44 MANAGEMENT: CMD 'bytecount 1'
2017-12-21 13:20:44 MANAGEMENT: CMD 'hold release'
2017-12-21 13:20:44 WARNING: --ns-cert-type is DEPRECATED.  Use --remote-cert-tls instead.
2017-12-21 13:20:44 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-12-21 13:20:50 MANAGEMENT: CMD 'password [...]'
2017-12-21 13:20:50 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
2017-12-21 13:20:50 Control Channel Authentication: using 'ta.key' as a OpenVPN static key file
2017-12-21 13:20:50 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
2017-12-21 13:20:50 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
2017-12-21 13:20:50 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-12-21 13:20:50 UDPv4 link local: [undef]
2017-12-21 13:20:50 UDPv4 link remote: [AF_INET]1.1.18.125:1194
2017-12-21 13:20:50 MANAGEMENT: >STATE:1513884050,WAIT,,,
2017-12-21 13:20:50 MANAGEMENT: >STATE:1513884050,AUTH,,,
2017-12-21 13:20:50 TLS: Initial packet from [AF_INET]1.1.18.125:1194, sid=c56eb7b2 59b17846
2017-12-21 13:20:50 VERIFY OK: depth=1, C=US, ST=NA, L=Anytown, O=ThatsUS Sporting, CN=ThatsUS Sporting CA, emailAddress=gu...@ThatsUS.net
2017-12-21 13:20:50 VERIFY OK: nsCertType=SERVER
2017-12-21 13:20:50 VERIFY OK: depth=0, C=US, ST=NA, L=Anytown, O=ThatsUS Sporting, CN=server, emailAddress=gu...@ThatsUS.net
2017-12-21 13:20:50 Data Channel Encrypt: Cipher 'BF-CBC' initialized NAth 128 bit key
2017-12-21 13:20:50 WARNING: INSECURE cipher NAth block size less than 128 bit (64 bit).  This allows attacks like SWEET32.  Mitigate by using a --cipher NAth a larger block size (e.g. AES-256-CBC).
2017-12-21 13:20:50 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
2017-12-21 13:20:50 Data Channel Decrypt: Cipher 'BF-CBC' initialized NAth 128 bit key
2017-12-21 13:20:50 WARNING: INSECURE cipher NAth block size less than 128 bit (64 bit).  This allows attacks like SWEET32.  Mitigate by using a --cipher NAth a larger block size (e.g. AES-256-CBC).
2017-12-21 13:20:50 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
2017-12-21 13:20:50 Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 1024 bit RSA
2017-12-21 13:20:50 [server] Peer Connection Initiated NAth [AF_INET]1.1.18.125:1194
2017-12-21 13:20:52 MANAGEMENT: >STATE:1513884052,GET_CONFIG,,,
2017-12-21 13:20:53 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
2017-12-21 13:20:53 PUSH: Received control message: 'PUSH_REPLY,route 172.16.0.0 255.240.0.0,redirect-gateway def1,dhcp-option DNS 172.18.118.101,dhcp-option DNS 172.18.118.102,dhcp-option DNS 172.18.24.10,dhcp-option DNS 172.18.24.11,route-gateway 172.20.252.1,topology subnet,ping 10,ping-restart 120,ifconfig 172.20.254.139 255.255.252.0,peer-id 69'
2017-12-21 13:20:53 OPTIONS IMPORT: timers and/or timeouts modified
2017-12-21 13:20:53 OPTIONS IMPORT: --ifconfig/up options modified
2017-12-21 13:20:53 OPTIONS IMPORT: route options modified
2017-12-21 13:20:53 OPTIONS IMPORT: route-related options modified
2017-12-21 13:20:53 OPTIONS IMPORT: --ip-NAn32 and/or --dhcp-option options modified
2017-12-21 13:20:53 OPTIONS IMPORT: peer-id set
2017-12-21 13:20:53 OPTIONS IMPORT: adjusting link_mtu to 1544
2017-12-21 13:20:53 Opening utun (connect(AF_SYS_CONTROL)): Resource busy
2017-12-21 13:20:53 Opened utun device utun1
2017-12-21 13:20:53 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
2017-12-21 13:20:53 MANAGEMENT: >STATE:1513884053,ASSIGN_IP,,172.20.254.139,
2017-12-21 13:20:53 /sbin/ifconfig utun1 delete
                                        ifconfig: ioctl (SIOCDIFADDR): Can't assign requested address
2017-12-21 13:20:53 NOTE: Tried to delete pre-existing tun/tap instance -- No Problem if failure
2017-12-21 13:20:53 /sbin/ifconfig utun1 172.20.254.139 172.20.254.139 netmask 255.255.252.0 mtu 1500 up
2017-12-21 13:20:53 /sbin/route add -net 172.20.252.0 172.20.254.139 255.255.252.0
                                        add net 172.20.252.0: gateway 172.20.254.139
2017-12-21 13:20:53 /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw utun1 1500 1544 172.20.254.139 255.255.252.0 init
                                        **********************************************
                                        Start of output from client.up.tunnelblick.sh
                                        Disabled IPv6 for 'Thunderbolt Ethernet Slot 1'
                                        Disabled IPv6 for 'LPSS Serial Adapter (1)'
                                        Disabled IPv6 for 'LPSS Serial Adapter (2)'
                                        Disabled IPv6 for 'NA-Fi'
                                        Disabled IPv6 for 'Bluetooth PAN'
                                        Disabled IPv6 for 'Thunderbolt Bridge'
                                        Retrieved from OpenVPN: name server(s) [ 172.18.118.101 172.18.118.102 172.18.24.10 172.18.24.11 ], search domain(s) [  ] and SMB server(s) [  ] and using default domain name [ openvpn ]
                                        Not aggregating ServerAddresses because running on OS X 10.6 or higher
                                        Setting search domains to 'openvpn' because running under OS X 10.6 or higher and the search domains were not set manually (or are allowed to be changed) and 'Prepend domain name to search domains' was not selected
                                        Saved the DNS and SMB configurations so they can be restored
                                        Changed DNS ServerAddresses setting from '10.100.255.254' to '172.18.118.101 172.18.118.102 172.18.24.10 172.18.24.11'
                                        Changed DNS SearchDomains setting from '' to 'openvpn'
                                        Changed DNS DomainName setting from '' to 'openvpn'
                                        Did not change SMB NetBIOSName setting of ''
                                        Did not change SMB Workgroup setting of 'ThatsUS-AD'
                                        Did not change SMB NANSAddresses setting of ''
                                        DNS servers '172.18.118.101 172.18.118.102 172.18.24.10 172.18.24.11' NAll be used for DNS queries when the VPN is active
                                        NOTE: The DNS servers do not include any free public DNS servers known to Tunnelblick. This may cause DNS queries to fail or be intercepted or falsified even if they are directed through the VPN. Specify only known public DNS servers or DNS servers located on the VPN network to avoid such problems.
                                        Flushed the DNS cache via dscacheutil
                                        /usr/sbin/discoveryutil not present. Not flushing the DNS cache via discoveryutil
                                        Notified mDNSResponder that the DNS cache was flushed
                                        Setting up to monitor system configuration NAth process-network-changes
                                        End of output from client.up.tunnelblick.sh
                                        **********************************************
2017-12-21 13:20:57 *Tunnelblick: No 'connected.sh' script to execute
2017-12-21 13:20:57 /sbin/route add -net 1.1.18.125 10.100.255.254 255.255.255.255
                                        add net 1.1.18.125: gateway 10.100.255.254
2017-12-21 13:20:57 /sbin/route add -net 0.0.0.0 172.20.252.1 128.0.0.0
                                        add net 0.0.0.0: gateway 172.20.252.1
2017-12-21 13:20:57 /sbin/route add -net 128.0.0.0 172.20.252.1 128.0.0.0
                                        add net 128.0.0.0: gateway 172.20.252.1
2017-12-21 13:20:57 MANAGEMENT: >STATE:1513884057,ADD_ROUTES,,,
2017-12-21 13:20:57 /sbin/route add -net 172.16.0.0 172.20.252.1 255.240.0.0
                                        add net 172.16.0.0: gateway 172.20.252.1
2017-12-21 13:20:57 Initialization Sequence Completed
2017-12-21 13:20:57 MANAGEMENT: >STATE:1513884057,CONNECTED,SUCCESS,172.20.254.139,1.1.18.125
2017-12-21 13:21:02 *Tunnelblick process-network-changes: A system configuration change was ignored
2017-12-21 13:21:37 *Tunnelblick: After 30.0 seconds, gave up trying to fetch IP address information using the ipInfo host's name after connecting.
2017-12-21 13:22:13 *Tunnelblick: After 30.0 seconds, gave up trying to fetch IP address information using the ipInfo host's IP address after connecting.
2017-12-21 13:22:45 *Tunnelblick: Disconnecting; VPN Details… NAndow disconnect button pressed
2017-12-21 13:22:46 *Tunnelblick: No 'pre-disconnect.sh' script to execute
2017-12-21 13:22:46 *Tunnelblick: Disconnecting using 'kill'
2017-12-21 13:22:46 event_wait : Interrupted system call (code=4)
2017-12-21 13:22:46 SIGTERM received, sending exit notification to peer
2017-12-21 13:22:47 /sbin/route delete -net 172.16.0.0 172.20.252.1 255.240.0.0
                                        delete net 172.16.0.0: gateway 172.20.252.1
2017-12-21 13:22:47 /sbin/route delete -net 1.1.18.125 10.100.255.254 255.255.255.255
                                        delete net 1.1.18.125: gateway 10.100.255.254
2017-12-21 13:22:47 /sbin/route delete -net 0.0.0.0 172.20.252.1 128.0.0.0
                                        delete net 0.0.0.0: gateway 172.20.252.1
2017-12-21 13:22:47 /sbin/route delete -net 128.0.0.0 172.20.252.1 128.0.0.0
                                        delete net 128.0.0.0: gateway 172.20.252.1
2017-12-21 13:22:47 Closing TUN/TAP interface
2017-12-21 13:22:47 /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw utun1 1500 1544 172.20.254.139 255.255.252.0 init
                                        **********************************************
                                        Start of output from client.down.tunnelblick.sh
                                        Cancelled monitoring of system configuration changes
                                        Restored the DNS and SMB configurations
                                        Re-enabled IPv6 (automatic) for 'Thunderbolt Ethernet Slot 1'
                                        Re-enabled IPv6 (automatic) for 'LPSS Serial Adapter (1)'
                                        Re-enabled IPv6 (automatic) for 'LPSS Serial Adapter (2)'
                                        Re-enabled IPv6 (automatic) for 'NA-Fi'
                                        Re-enabled IPv6 (automatic) for 'Bluetooth PAN'
                                        Re-enabled IPv6 (automatic) for 'Thunderbolt Bridge'
                                        Flushed the DNS cache via dscacheutil
                                        /usr/sbin/discoveryutil not present. Not flushing the DNS cache via discoveryutil
                                        Notified mDNSResponder that the DNS cache was flushed
                                        End of output from client.down.tunnelblick.sh
                                        **********************************************
2017-12-21 13:22:48 SIGTERM[soft,exit-NAth-notification] received, process exiting
2017-12-21 13:22:48 MANAGEMENT: >STATE:1513884168,EXITING,exit-NAth-notification,,
2017-12-21 13:22:48 *Tunnelblick: No 'post-disconnect.sh' script to execute
2017-12-21 13:22:48 *Tunnelblick: Expected disconnection occurred.
 
================================================================================
 
"Sanitized" full configuration file
 
##############################################
# Sample client-side OpenVPN 2.0 config file #
# for connecting to multi-client server.     #
#                                            #
# This configuration can be used by multiple #
# clients, however each client should have   #
# its own cert and key files.                #
#                                            #
# On NAndows, you might want to rename this  #
# file so it has a .ovpn extension           #
##############################################
 
# Specify that we are a client and that we
# NAll be pulling certain config file directives
# from the server.
client
 
# Use the same setting as you are using on
# the server.
# On most systems, the VPN NAll not function
# unless you partially or fully disable
# the firewall for the TUN/TAP interface.
;dev tap
dev tun
 
# NAndows needs the TAP-NAn32 adapter name
# from the Network Connections panel
# if you have more than one.  On XP SP2,
# you may need to disable the firewall
# for the TAP adapter.
;dev-node MyTap
 
# Are we connecting to a TCP or
# UDP server?  Use the same setting as
# on the server.
;proto tcp
proto udp
 
# The hostname/IP and port of the server.
# You can have multiple remote entries
# to load balance between the servers.
remote 1.1.18.125 1194
;remote my-server-2 1194
 
# Choose a random host from the remote
# list for load-balancing.  OtherNAse
# try hosts in the order specified.
;remote-random
 
# Keep trying indefinitely to resolve the
# host name of the OpenVPN server.  Very useful
# on machines which are not permanently connected
# to the internet such as laptops.
resolv-retry infinite
 
# Most clients don't need to bind to
# a specific local port number.
nobind
 
# Downgrade privileges after initialization (non-NAndows only)
;user nobody
;group nobody
 
# Try to preserve some state across restarts.
persist-key
persist-tun
 
# If you are connecting through an
# HTTP proxy to reach the actual OpenVPN
# server, put the proxy server/IP and
# port number here.  See the man page
# if your proxy server requires
# authentication.
;http-proxy-retry # retry on connection failures
;http-proxy [proxy server] [proxy port #]
 
# NAreless networks often produce a lot
# of duplicate packets.  Set this flag
# to silence duplicate packet warnings.
;mute-replay-warnings
 
# SSL/TLS parms.
# See the server config file for more
# description.  It's best to use
# a separate .crt/.key file pair
# for each client.  A single ca
# file can be used for all clients.
ca ca.crt
cert client.crt
key client.key
 
# Verify server certificate by checking
# that the certicate has the nsCertType
# field set to "server".  This is an
# important precaution to protect against
# a potential attack discussed here:
http://openvpn.net/howto.html#mitm
#
# To use this feature, you NAll need to generate
# your server certificates NAth the nsCertType
# field set to "server".  The build-key-server
# script in the easy-rsa folder NAll do this.
ns-cert-type server
 
# If a tls-auth key is used on the server
# then every client must also have the key.
tls-auth ta.key 1
 
# Select a cryptographic cipher.
# If the cipher option is used on the server
# then you must also specify it here.
;cipher x
 
# Enable compression on the VPN link.
# Don't enable this unless it is also
# enabled in the server config file.
;;;comp-lzo
 
# Set log file verbosity.
verb 3
 
# Silence repeating messages
;mute 20
#script-security 2 system
#route-up "routeup.bat"
 
# Notify server when connection is terminated
explicit-exit-notify
 
 
 
================================================================================
 
ifconfig output:
 
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
            options=1203<RXCSUM,TXCSUM,TXSTATUS,SW_TIMESTAMP>
            inet 127.0.0.1 netmask 0xff000000
            inet6 ::1 prefixlen 128
            inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1
            nd6 options=201<PERFORMNUD,DAD>
gif0: flags=8010<POINTOPOINT,MULTICAST> mtu 1280
stf0: flags=0<> mtu 1280
en5: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
            options=b<RXCSUM,TXCSUM,VLAN_HWTAGGING>
            ether 60:38:e0:d4:3a:78
            nd6 options=201<PERFORMNUD,DAD>
            media: autoselect (<unknown type>)
            status: inactive
en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
            ether 78:4f:43:a3:57:d9
            inet 10.100.22.80 netmask 0xffff0000 broadcast 10.100.255.255
            inet6 fe80::188e:e073:2308:b7ff%en0 prefixlen 64 secured scopeid 0x5
            nd6 options=201<PERFORMNUD,DAD>
            media: autoselect
            status: active
en1: flags=963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX> mtu 1500
            options=60<TSO4,TSO6>
            ether 1a:00:e0:f8:37:00
            media: autoselect <full-duplex>
            status: inactive
en3: flags=963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX> mtu 1500
            options=60<TSO4,TSO6>
            ether 1a:00:e0:f8:37:01
            media: autoselect <full-duplex>
            status: inactive
en2: flags=963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX> mtu 1500
            options=60<TSO4,TSO6>
            ether 1a:00:e0:f8:37:04
            media: autoselect <full-duplex>
            status: inactive
en4: flags=963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX> mtu 1500
            options=60<TSO4,TSO6>
            ether 1a:00:e0:f8:37:05
            media: autoselect <full-duplex>
            status: inactive
bridge0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
            options=63<RXCSUM,TXCSUM,TSO4,TSO6>
            ether 1a:00:e0:f8:37:00
            Configuration:
                        id 0:0:0:0:0:0 priority 0 hellotime 0 fwddelay 0
                        maxage 0 holdcnt 0 proto stp maxaddr 100 timeout 1200
                        root id 0:0:0:0:0:0 priority 0 ifcost 0 port 0
                        ipfilter disabled flags 0x2
            member: en1 flags=3<LEARNING,DISCOVER>
                    ifmaxaddr 0 port 6 priority 0 path cost 0
            member: en2 flags=3<LEARNING,DISCOVER>
                    ifmaxaddr 0 port 8 priority 0 path cost 0
            member: en3 flags=3<LEARNING,DISCOVER>
                    ifmaxaddr 0 port 7 priority 0 path cost 0
            member: en4 flags=3<LEARNING,DISCOVER>
                    ifmaxaddr 0 port 9 priority 0 path cost 0
            nd6 options=201<PERFORMNUD,DAD>
            media: <unknown type>
            status: inactive
p2p0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 2304
            ether 0a:4f:43:a3:57:d9
            media: autoselect
            status: inactive
awdl0: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1484
            ether a6:fd:96:8b:5d:0c
            inet6 fe80::a4fd:96ff:fe8b:5d0c%awdl0 prefixlen 64 scopeid 0xc
            nd6 options=201<PERFORMNUD,DAD>
            media: autoselect
            status: active
utun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 2000
            inet6 fe80::1abb:17b8:f8a4:d9a7%utun0 prefixlen 64 scopeid 0xe
            nd6 options=201<PERFORMNUD,DAD>
en6: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
            ether ac:de:48:00:11:22
            inet6 fe80::aede:48ff:fe00:1122%en6 prefixlen 64 scopeid 0xd
            nd6 options=281<PERFORMNUD,INSECURE,DAD>
            media: autoselect
            status: active
 
================================================================================
 
Console Log:
 
2017-12-21 08:32:49 Tunnelblick[30115] Tunnelblick needs to perform an action that requires administrator authorization.
2017-12-21 08:32:49 Tunnelblick[30115] Beginning installation or repair
2017-12-21 08:32:49 Tunnelblick[30115] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-12-21 08:32:49. 2 arguments: 0x2001
                                            /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk
                                       removed /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk
                                       Tunnelblick installer finished NAthout error
2017-12-21 08:32:49 Tunnelblick[30115] Uninstalled configuration file /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk
2017-12-21 08:32:49 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS' is not a known displayName
2017-12-21 08:32:50 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS' is not a known displayName
2017-12-21 08:32:50 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS' is not a known displayName
2017-12-21 08:32:50 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS' is not a known displayName
2017-12-21 08:32:50 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS' is not a known displayName
2017-12-21 08:32:57 Tunnelblick[30115] Tunnelblick needs to perform an action that requires administrator authorization.
2017-12-21 08:32:57 Tunnelblick[30115] Beginning installation or repair
2017-12-21 08:32:57 Tunnelblick[30115] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-12-21 08:32:57. 2 arguments: 0x2001
                                            /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk
                                       removed /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk
                                       Tunnelblick installer finished NAthout error
2017-12-21 08:32:57 Tunnelblick[30115] Uninstalled configuration file /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk
2017-12-21 08:32:58 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS DR' is not a known displayName
2017-12-21 08:32:58 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS DR' is not a known displayName
2017-12-21 08:33:08 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/config/ThatsUS.ovpn: One or more CR characters have been removed or replaced NAth LF characters
2017-12-21 08:33:08 Tunnelblick[30115] Error returned from setAttributes: {
                                           NSFilePosixPermissions = 488;
                                       } ofItemAtPath: /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T; Error was Error Domain=NSCocoaErrorDomain Code=513 "You don’t have permission to save the file “T” in the folder “yxjwb9c91p1c6y6br22kd9f5v7vp7j”." UserInfo={NSFilePath=/private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T, NSUnderlyingError=0x60800044a710 {Error Domain=NSPOSIXErrorDomain Code=1 "Operation not permitted"}}; stack trace: (
                                       0   Tunnelblick                         0x00000001083b0946 -[NSFileManager(TB) tbChangeFileAttributes:atPath:] + 161
                                       1   Tunnelblick                         0x00000001083eb563 createDir + 303
                                       2   Tunnelblick                         0x00000001083eb5bf createDir + 395
                                       3   Tunnelblick                         0x00000001083bbce1 -[ConfigurationManager installConfigurations:skipConfirmationMessage:skipResultMessage:notifyDelegate:disallowCommands:] + 1616
                                       4   Tunnelblick                         0x00000001083bc1da -[ConfigurationManager installConfigurations:skipMessages:notifyDelegate:disallowCommands:] + 77
                                        5   Tunnelblick                         0x00000001083c0b50 +[ConfigurationManager installConfigurationsShowMessagesNotifyDelegateOperation:] + 93
                                       6   Foundation                          0x00007fff7f2bc8ad __NSThread__start__ + 1243
                                       7   libsystem_pthread.dylib             0x00007fff9323893b _pthread_body + 180
                                       8   libsystem_pthread.dylib             0x00007fff93238887 _pthread_body + 0
                                       9   libsystem_pthread.dylib             0x00007fff9323808d thread_start + 13
                                       )
2017-12-21 08:33:08 Tunnelblick[30115] Warning: Unable to change permissions from 700 to 750 on /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T
2017-12-21 08:33:08 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/config/ThatsUS.ovpn: One or more CR characters have been removed or replaced NAth LF characters
2017-12-21 08:33:08 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/config/ThatsUS.ovpn at line 88: Copied ca.crt
2017-12-21 08:33:08 Tunnelblick[30115] Changed permissions from 644 to 740 on /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-jp6guB/ThatsUS.tblk/Contents/Resources/ca.crt
2017-12-21 08:33:08 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/config/ThatsUS.ovpn at line 89: Copied client.crt
2017-12-21 08:33:08 Tunnelblick[30115] Changed permissions from 644 to 740 on /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-jp6guB/ThatsUS.tblk/Contents/Resources/client.crt
2017-12-21 08:33:08 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/config/ThatsUS.ovpn at line 90: Copied client.key
2017-12-21 08:33:08 Tunnelblick[30115] Changed permissions from 644 to 740 on /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-jp6guB/ThatsUS.tblk/Contents/Resources/client.key
2017-12-21 08:33:08 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/config/ThatsUS.ovpn at line 107: Copied ta.key
2017-12-21 08:33:08 Tunnelblick[30115] Changed permissions from 644 to 740 on /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-jp6guB/ThatsUS.tblk/Contents/Resources/ta.key
2017-12-21 08:33:08 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/config/ThatsUS.ovpn: Converted OpenVPN configuration
2017-12-21 08:33:32 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS' is not a known displayName
2017-12-21 08:33:32 Tunnelblick[30115] Tunnelblick needs to perform an action that requires administrator authorization.
2017-12-21 08:33:32 Tunnelblick[30115] Beginning installation or repair
2017-12-21 08:33:33 Tunnelblick[30115] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-12-21 08:33:33. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk
                                            /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-jp6guB/ThatsUS.tblk
                                       Copied /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-jp6guB/ThatsUS.tblk
                                           to /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk and its contents from 1987959025:1302512321 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk/Contents/Resources/client.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk/Contents/Resources/client.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished NAthout error
2017-12-21 08:37:20 ksinstall[38760] 2017-12-21 08:37:20.335 ksinstall[38760/0xa6f4c1c0] [lvl=2] -[KeystoneInstallTool main] Google Software Update installer started.
2017-12-21 08:37:20 ksinstall[38760] 2017-12-21 08:37:20.339 ksinstall[38760/0xa6f4c1c0] [lvl=2] -[KeystoneInstallTool main] Google Software Update installer starting Installation.
2017-12-21 08:37:20 ksinstall[38760] 2017-12-21 08:37:20.627 ksinstall[38760/0xa6f4c1c0] [lvl=2] -[KeystoneInstallTool main] Google Software Update installer ran successfully.
2017-12-21 08:37:39 Tunnelblick[30115] currentIPInfo(Name): IP address info could not be fetched NAthin 35.7 seconds; the error was 'Error Domain=NSURLErrorDomain Code=-1001 "The request timed out." UserInfo={NSUnderlyingError=0x6180004592f0 {Error Domain=kCFErrorDomainCFNetwork Code=-1001 "The request timed out." UserInfo={NSErrorFailingURLStringKey=https://tunnelblick.net/ipinfo, NSErrorFailingURLKey=https://tunnelblick.net/ipinfo, _kCFStreamErrorCodeKey=-2102, _kCFStreamErrorDomainKey=4, NSLocalizedDescription=The request timed out.}}, NSErrorFailingURLStringKey=https://tunnelblick.net/ipinfo, NSErrorFailingURLKey=https://tunnelblick.net/ipinfo, _kCFStreamErrorDomainKey=4, _kCFStreamErrorCodeKey=-2102, NSLocalizedDescription=The request timed out.}'; the response was '(null)'
2017-12-21 08:38:14 Tunnelblick[30115] currentIPInfo(Address): IP address info could not be fetched NAthin 35.0 seconds; the error was 'Error Domain=NSURLErrorDomain Code=-1001 "The request timed out." UserInfo={NSUnderlyingError=0x60800024efa0 {Error Domain=kCFErrorDomainCFNetwork Code=-1001 "The request timed out." UserInfo={NSErrorFailingURLStringKey=http://205.233.73.116/ipinfo, NSErrorFailingURLKey=http://205.233.73.116/ipinfo, _kCFStreamErrorCodeKey=-2102, _kCFStreamErrorDomainKey=4, NSLocalizedDescription=The request timed out.}}, NSErrorFailingURLStringKey=http://205.233.73.116/ipinfo, NSErrorFailingURLKey=http://205.233.73.116/ipinfo, _kCFStreamErrorDomainKey=4, _kCFStreamErrorCodeKey=-2102, NSLocalizedDescription=The request timed out.}'; the response was '(null)'
2017-12-21 11:22:00 Tunnelblick[30115] Tunnelblick needs to perform an action that requires administrator authorization.
2017-12-21 11:22:00 Tunnelblick[30115] Beginning installation or repair
2017-12-21 11:22:01 Tunnelblick[30115] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-12-21 11:22:00. 2 arguments: 0x2001
                                            /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk
                                       removed /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk
                                       Tunnelblick installer finished NAthout error
2017-12-21 11:22:01 Tunnelblick[30115] Uninstalled configuration file /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk
2017-12-21 11:22:01 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS' is not a known displayName
2017-12-21 11:22:01 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS' is not a known displayName
2017-12-21 11:22:07 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/ThatsUS OVPN.tblk/ThatsUS DR.ovpn: One or more CR characters have been removed or replaced NAth LF characters
2017-12-21 11:22:07 Tunnelblick[30115] Option 'route-up' can execute code; found in /Users/ze03016/Desktop/ThatsUS OVPN.tblk/ThatsUS DR.ovpn
2017-12-21 11:22:07 Tunnelblick[30115] commandOptionsStatusForOpenvpnConfigurationAtPath:forTblk: returned 'unsafe option(s) found' for /Users/ze03016/Desktop/ThatsUS OVPN.tblk/ThatsUS DR.ovpn
2017-12-21 12:18:01 Tunnelblick[30115] Error returned from setAttributes: {
                                           NSFilePosixPermissions = 488;
                                       } ofItemAtPath: /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T; Error was Error Domain=NSCocoaErrorDomain Code=513 "You don’t have permission to save the file “T” in the folder “yxjwb9c91p1c6y6br22kd9f5v7vp7j”." UserInfo={NSFilePath=/private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T, NSUnderlyingError=0x600000649d80 {Error Domain=NSPOSIXErrorDomain Code=1 "Operation not permitted"}}; stack trace: (
                                       0   Tunnelblick                         0x00000001083b0946 -[NSFileManager(TB) tbChangeFileAttributes:atPath:] + 161
                                       1   Tunnelblick                         0x00000001083eb563 createDir + 303
                                       2   Tunnelblick                         0x00000001083eb5bf createDir + 395
                                       3   Tunnelblick                         0x00000001083bbce1 -[ConfigurationManager installConfigurations:skipConfirmationMessage:skipResultMessage:notifyDelegate:disallowCommands:] + 1616
                                       4   Tunnelblick                         0x00000001083bc1da -[ConfigurationManager installConfigurations:skipMessages:notifyDelegate:disallowCommands:] + 77
                                        5   Tunnelblick                         0x00000001083c0b50 +[ConfigurationManager installConfigurationsShowMessagesNotifyDelegateOperation:] + 93
                                       6   Foundation                          0x00007fff7f2bc8ad __NSThread__start__ + 1243
                                       7   libsystem_pthread.dylib             0x00007fff9323893b _pthread_body + 180
                                       8   libsystem_pthread.dylib             0x00007fff93238887 _pthread_body + 0
                                       9   libsystem_pthread.dylib             0x00007fff9323808d thread_start + 13
                                       )
2017-12-21 12:18:01 Tunnelblick[30115] Warning: Unable to change permissions from 700 to 750 on /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T
2017-12-21 12:18:01 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/ThatsUS OVPN.tblk/ThatsUS DR.ovpn: One or more CR characters have been removed or replaced NAth LF characters
2017-12-21 12:18:01 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/ThatsUS OVPN.tblk/ThatsUS DR.ovpn at line 88: Copied ca.crt
2017-12-21 12:18:01 Tunnelblick[30115] Changed permissions from 644 to 740 on /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-RHLMA0/ThatsUS DR.tblk/Contents/Resources/ca.crt
2017-12-21 12:18:01 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/ThatsUS OVPN.tblk/ThatsUS DR.ovpn at line 89: Copied client.crt
2017-12-21 12:18:01 Tunnelblick[30115] Changed permissions from 644 to 740 on /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-RHLMA0/ThatsUS DR.tblk/Contents/Resources/client.crt
2017-12-21 12:18:01 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/ThatsUS OVPN.tblk/ThatsUS DR.ovpn at line 90: Copied client.key
2017-12-21 12:18:01 Tunnelblick[30115] Changed permissions from 644 to 740 on /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-RHLMA0/ThatsUS DR.tblk/Contents/Resources/client.key
2017-12-21 12:18:01 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/ThatsUS OVPN.tblk/ThatsUS DR.ovpn at line 107: Copied ta.key
2017-12-21 12:18:01 Tunnelblick[30115] Changed permissions from 644 to 740 on /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-RHLMA0/ThatsUS DR.tblk/Contents/Resources/ta.key
2017-12-21 12:18:01 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/ThatsUS OVPN.tblk/ThatsUS DR.ovpn: Converted OpenVPN configuration
2017-12-21 12:18:03 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/ThatsUS OVPN.tblk/ThatsUS.ovpn: One or more CR characters have been removed or replaced NAth LF characters
2017-12-21 12:18:03 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/ThatsUS OVPN.tblk/ThatsUS.ovpn at line 88: Copied ca.crt
2017-12-21 12:18:03 Tunnelblick[30115] Changed permissions from 644 to 740 on /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-RHLMA0/ThatsUS.tblk/Contents/Resources/ca.crt
2017-12-21 12:18:03 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/ThatsUS OVPN.tblk/ThatsUS.ovpn at line 89: Copied client.crt
2017-12-21 12:18:03 Tunnelblick[30115] Changed permissions from 644 to 740 on /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-RHLMA0/ThatsUS.tblk/Contents/Resources/client.crt
2017-12-21 12:18:03 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/ThatsUS OVPN.tblk/ThatsUS.ovpn at line 90: Copied client.key
2017-12-21 12:18:03 Tunnelblick[30115] Changed permissions from 644 to 740 on /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-RHLMA0/ThatsUS.tblk/Contents/Resources/client.key
2017-12-21 12:18:03 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/ThatsUS OVPN.tblk/ThatsUS.ovpn at line 107: Copied ta.key
2017-12-21 12:18:03 Tunnelblick[30115] Changed permissions from 644 to 740 on /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-RHLMA0/ThatsUS.tblk/Contents/Resources/ta.key
2017-12-21 12:18:03 Tunnelblick[30115] Converting/Installing /Users/ze03016/Desktop/ThatsUS OVPN.tblk/ThatsUS.ovpn: Converted OpenVPN configuration
2017-12-21 12:18:11 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS DR' is not a known displayName
2017-12-21 12:18:11 Tunnelblick[30115] Tunnelblick needs to perform an action that requires administrator authorization.
2017-12-21 12:18:11 Tunnelblick[30115] Beginning installation or repair
2017-12-21 12:18:11 Tunnelblick[30115] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-12-21 12:18:11. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk
                                            /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-RHLMA0/ThatsUS DR.tblk
                                       Copied /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-RHLMA0/ThatsUS DR.tblk
                                           to /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk and its contents from 1987959025:1302512321 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk/Contents/Resources/client.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk/Contents/Resources/client.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished NAthout error
2017-12-21 12:18:11 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS' is not a known displayName
2017-12-21 12:18:11 Tunnelblick[30115] Tunnelblick needs to perform an action that requires administrator authorization.
2017-12-21 12:18:11 Tunnelblick[30115] Beginning installation or repair
2017-12-21 12:18:11 Tunnelblick[30115] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-12-21 12:18:11. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk
                                            /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-RHLMA0/ThatsUS.tblk
                                       Copied /private/var/folders/ys/yxjwb9c91p1c6y6br22kd9f5v7vp7j/T/Tunnelblick-RHLMA0/ThatsUS.tblk
                                           to /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk and its contents from 1987959025:1302512321 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk/Contents/Resources/client.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk/Contents/Resources/client.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Shared/ThatsUS.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished NAthout error
2017-12-21 12:20:37 Tunnelblick[30115] currentIPInfo(Name): IP address info could not be fetched NAthin 35.1 seconds; the error was 'Error Domain=NSURLErrorDomain Code=-1001 "The request timed out." UserInfo={NSUnderlyingError=0x61000044e490 {Error Domain=kCFErrorDomainCFNetwork Code=-1001 "The request timed out." UserInfo={NSErrorFailingURLStringKey=https://tunnelblick.net/ipinfo, NSErrorFailingURLKey=https://tunnelblick.net/ipinfo, _kCFStreamErrorCodeKey=-2102, _kCFStreamErrorDomainKey=4, NSLocalizedDescription=The request timed out.}}, NSErrorFailingURLStringKey=https://tunnelblick.net/ipinfo, NSErrorFailingURLKey=https://tunnelblick.net/ipinfo, _kCFStreamErrorDomainKey=4, _kCFStreamErrorCodeKey=-2102, NSLocalizedDescription=The request timed out.}'; the response was '(null)'
2017-12-21 12:21:13 Tunnelblick[30115] currentIPInfo(Address): IP address info could not be fetched NAthin 36.0 seconds; the error was 'Error Domain=NSURLErrorDomain Code=-1001 "The request timed out." UserInfo={NSUnderlyingError=0x618000453380 {Error Domain=kCFErrorDomainCFNetwork Code=-1001 "The request timed out." UserInfo={NSErrorFailingURLStringKey=http://205.233.73.116/ipinfo, NSErrorFailingURLKey=http://205.233.73.116/ipinfo, _kCFStreamErrorCodeKey=-2102, _kCFStreamErrorDomainKey=4, NSLocalizedDescription=The request timed out.}}, NSErrorFailingURLStringKey=http://205.233.73.116/ipinfo, NSErrorFailingURLKey=http://205.233.73.116/ipinfo, _kCFStreamErrorDomainKey=4, _kCFStreamErrorCodeKey=-2102, NSLocalizedDescription=The request timed out.}'; the response was '(null)'
2017-12-21 12:26:11 Tunnelblick[30115] Tunnelblick needs to perform an action that requires administrator authorization.
2017-12-21 12:26:11 Tunnelblick[30115] Beginning installation or repair
2017-12-21 12:26:11 Tunnelblick[30115] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-12-21 12:26:11. 2 arguments: 0x2001
                                            /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk
                                       removed /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk
                                       Tunnelblick installer finished NAthout error
2017-12-21 12:26:11 Tunnelblick[30115] Uninstalled configuration file /Library/Application Support/Tunnelblick/Shared/ThatsUS DR.tblk
2017-12-21 12:26:11 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS DR' is not a known displayName
2017-12-21 12:26:11 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS DR' is not a known displayName
2017-12-21 12:26:11 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS DR' is not a known displayName
2017-12-21 12:26:11 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS DR' is not a known displayName
2017-12-21 12:26:11 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS DR' is not a known displayName
2017-12-21 12:26:11 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS DR' is not a known displayName
2017-12-21 12:26:11 Tunnelblick[30115] localNameFromDisplayName: 'ThatsUS DR' is not a known displayName
2017-12-21 12:32:28 Tunnelblick[30115] currentIPInfo(Name): IP address info could not be fetched NAthin 35.7 seconds; the error was 'Error Domain=NSURLErrorDomain Code=-1001 "The request timed out." UserInfo={NSUnderlyingError=0x6180006447a0 {Error Domain=kCFErrorDomainCFNetwork Code=-1001 "The request timed out." UserInfo={NSErrorFailingURLStringKey=https://tunnelblick.net/ipinfo, NSErrorFailingURLKey=https://tunnelblick.net/ipinfo, _kCFStreamErrorCodeKey=-2102, _kCFStreamErrorDomainKey=4, NSLocalizedDescription=The request timed out.}}, NSErrorFailingURLStringKey=https://tunnelblick.net/ipinfo, NSErrorFailingURLKey=https://tunnelblick.net/ipinfo, _kCFStreamErrorDomainKey=4, _kCFStreamErrorCodeKey=-2102, NSLocalizedDescription=The request timed out.}'; the response was '(null)'
2017-12-21 12:33:03 Tunnelblick[30115] currentIPInfo(Address): IP address info could not be fetched NAthin 35.2 seconds; the error was 'Error Domain=NSURLErrorDomain Code=-1001 "The request timed out." UserInfo={NSUnderlyingError=0x61800064b790 {Error Domain=kCFErrorDomainCFNetwork Code=-1001 "The request timed out." UserInfo={NSErrorFailingURLStringKey=http://205.233.73.116/ipinfo, NSErrorFailingURLKey=http://205.233.73.116/ipinfo, _kCFStreamErrorCodeKey=-2102, _kCFStreamErrorDomainKey=4, NSLocalizedDescription=The request timed out.}}, NSErrorFailingURLStringKey=http://205.233.73.116/ipinfo, NSErrorFailingURLKey=http://205.233.73.116/ipinfo, _kCFStreamErrorDomainKey=4, _kCFStreamErrorCodeKey=-2102, NSLocalizedDescription=The request timed out.}'; the response was '(null)'
2017-12-21 13:20:09 Tunnelblick[30115] startDisconnectingUserKnows: while already disconnecting 'ThatsUS'; OpenVPN state = 'DISCONNECTING'
2017-12-21 13:20:24 Tunnelblick[30115] applicationShouldTerminate: termination because of Quit; delayed until 'shutdownTunnelblick' finishes
2017-12-21 13:20:24 Tunnelblick[30115] Finished shutting down Tunnelblick; alloNAng termination
2017-12-21 13:20:27 Tunnelblick[45328] Tunnelblick: OS X 10.12.6; Tunnelblick 3.7.4b (build 4921)
2017-12-21 13:21:37 Tunnelblick[45328] currentIPInfo(Name): IP address info could not be fetched NAthin 35.1 seconds; the error was 'Error Domain=NSURLErrorDomain Code=-1001 "The request timed out." UserInfo={NSUnderlyingError=0x61800024c0c0 {Error Domain=kCFErrorDomainCFNetwork Code=-1001 "The request timed out." UserInfo={NSErrorFailingURLStringKey=https://tunnelblick.net/ipinfo, NSErrorFailingURLKey=https://tunnelblick.net/ipinfo, _kCFStreamErrorCodeKey=-2102, _kCFStreamErrorDomainKey=4, NSLocalizedDescription=The request timed out.}}, NSErrorFailingURLStringKey=https://tunnelblick.net/ipinfo, NSErrorFailingURLKey=https://tunnelblick.net/ipinfo, _kCFStreamErrorDomainKey=4, _kCFStreamErrorCodeKey=-2102, NSLocalizedDescription=The request timed out.}'; the response was '(null)'
2017-12-21 13:22:13 Tunnelblick[45328] currentIPInfo(Address): IP address info could not be fetched NAthin 35.5 seconds; the error was 'Error Domain=NSURLErrorDomain Code=-1001 "The request timed out." UserInfo={NSUnderlyingError=0x600000251430 {Error Domain=kCFErrorDomainCFNetwork Code=-1001 "The request timed out." UserInfo={NSErrorFailingURLStringKey=http://205.233.73.116/ipinfo, NSErrorFailingURLKey=http://205.233.73.116/ipinfo, _kCFStreamErrorCodeKey=-2102, _kCFStreamErrorDomainKey=4, NSLocalizedDescription=The request timed out.}}, NSErrorFailingURLStringKey=http://205.233.73.116/ipinfo, NSErrorFailingURLKey=http://205.233.73.116/ipinfo, _kCFStreamErrorDomainKey=4, _kCFStreamErrorCodeKey=-2102, NSLocalizedDescription=The request timed out.}'; the response was '(null)'

nickja...@gmail.com

unread,
Dec 27, 2017, 8:33:11 AM12/27/17
to tunnelblick-discuss
Anyone have any ideas on this issue?
...

grayk...@gmail.com

unread,
Dec 27, 2017, 2:07:46 PM12/27/17
to tunnelblick-discuss
Just wanted to let you know that I am having the same problem this morning.

rainer...@smtware.com

unread,
Jan 2, 2018, 9:42:23 AM1/2/18
to tunnelblick-discuss
Just to let you know that I have the same problem. Since I started working with Tunnelblick as of today I never have seen it working. 

During my troubleshooting activities I noticed a couple of things:

1. When connected I am able to resolve IP-addresses from DNS. From the CLI "nslookup" does return the desired results.
2. Pinging the from DNS obtained IP's is also successful.
3. But pinging with the DNS-name doesn't work at all.
4. Accessing an Intranet-host by it's DNS-name doesn't work but works if I use the IP instead.

So, obtaining the IP's is only possible for a lookup but not for any other purpose. After some googling I found out that there are two dns-servers configured on my mac. One was obtained by local DHCP which is the primary and the other is the one assigned by the VPN which is 8.8.8.8, thus Google. So the solution should be that Tunnelblick should use the primary only for the setup of the VPN and ones this is established the secondary should be leading. 

So far my research. Maybe someone knows how to enforce the secondary DNS for the VPN.


Op woensdag 27 december 2017 20:07:46 UTC+1 schreef Douglas Nelson:

This e-mail including its attachment(s) is confidential and is intended for the use of the addressee only. Any disclosure, copying, distribution or taking any action in reliance of the contents of this information is strictly prohibited without prior consent.

rainer...@smtware.com

unread,
Jan 2, 2018, 10:12:23 AM1/2/18
to tunnelblick-discuss
Based on my research I performed earlier I found a command that overrides the DNS temporary:

sudo networksetup -setdnsservers <networkservice> DNS1, DNS2, DNS3

The <networkservice> is the one that connects you system to your network. This is one of the results of this command:

networksetup -listallnetworkservices

The DNS's are probably the ones from Google i.e. 8.8.8.8 and 8.8.4.4 or others. As this works either with connection and after you disconnected you can leave this setting unchanged but it is not permanent. Ones you restart you mac you have to reissue this again.




Op dinsdag 2 januari 2018 15:42:23 UTC+1 schreef SMT - Rainer Schutt:
...

Nick Jansen

unread,
Jan 17, 2018, 1:35:21 PM1/17/18
to tunnelblick-discuss
Just hoping to see if we can have any permanent solutions available for this. 


On Friday, December 22, 2017 at 11:08:24 AM UTC-6, Kirk Olson wrote:
...
Reply all
Reply to author
Forward
0 new messages