this computer's apparent public ip address was not different after connecting to client... tunnelblick

11,296 views
Skip to first unread message

rtmh...@gmail.com

unread,
Oct 14, 2017, 6:59:11 AM10/14/17
to tunnelblick-discuss
Hi Team,


I'm getting the below message after connected to VPN.

This computer's apparent public ip address was not different after connecting to client. It is still xxx.xxx.xxx.xxx. This mean that your VPN is not configured correctly

I'm using the following:

Server: OpenVPN
Client Version: Tunnelblick 3.7.3beta03 (build 4870)
OS: macOS Sierrra 10.2.6

Steps Taken:

1) I've tested connecting to openvpn using the same client.ovpn file on my iphone and it's working though.
2) I've tried using a diff DNS(no-ip) and it throws back the same error.



Below is the Log file:

*Tunnelblick: OS X 10.12.6; Tunnelblick 3.7.3beta03 (build 4870); prior version 3.7.2a (build 4851); Admin user
git commit b496ed5872cd9cf2b42372acd8a655a1c476250e


Configuration client

"Sanitized" condensed configuration file for /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk:

client
dev tun
proto udp
remote xxx.asuscomm.com 1194
float
cipher AES-128-CBC
comp-lzo adaptive
keepalive 15 60
auth-user-pass
ns-cert-type server
<ca>
[Security-related line(s) omitted]
</ca>
<cert>
[Security-related line(s) omitted]
</cert>
<key>
[Security-related line(s) omitted]
</key>
resolv-retry infinite
nobind


================================================================================

Non-Apple kexts that are loaded:

Index Refs Address            Size       Wired      Name (Version) UUID <Linked Against>
   15    0 0xffffff7f80d57000 0x8000     0x8000     com.cososys.driver.EPPDeviceController (1.11.8) C8C3E17C-8DA9-3E2F-BFD4-00C20660B69B <14 5 4 3 1>
  141    0 0xffffff7f80d4d000 0x2000     0x2000     com.cososys.kext.EPPUsbHelper (1.11.6) ED6A4EA4-1383-378D-9BE5-767256159938 <61 42>
  142    0 0xffffff7f80d50000 0x5000     0x5000     com.cososys.eppclient.eppkauth (1) 8CF99969-EC3D-36B9-B1B8-58DA23EC3412 <4 1>

================================================================================

There are no unusual files in client.tblk

================================================================================

Configuration preferences:

-keychainHasUsernameAndPassword = 1
-lastConnectionSucceeded = 1

================================================================================

Wildcard preferences:


================================================================================

Program preferences:

launchAtNextLogin = 1
notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0
askedUserIfOKToCheckThatIPAddressDidNotChangeAfterConnection = 1
tunnelblickVersionHistory = (
    "3.7.3beta03 (build 4870)",
    "3.7.2a (build 4851)"
)
lastLaunchTime = 529642763.020115
lastLanguageAtLaunchWasRTL = 0
connectionWindowDisplayCriteria = showWhenConnecting
maxLogDisplaySize = 102400
lastConnectedDisplayName = client
keyboardShortcutIndex = 1
updateCheckAutomatically = 1
updateCheckBetas = 1
updateSendProfileInfo = 1
NSWindow Frame SettingsSheetWindow = 752 379 829 524 0 0 1680 1028
NSWindow Frame ConnectingWindow = 645 641 389 187 0 0 1680 1028
NSWindow Frame SUUpdateAlert = 530 487 620 392 0 0 1680 1028
detailsWindowFrameVersion = 4851
detailsWindowFrame = {{724, 510}, {920, 468}}
detailsWindowLeftFrame = {{0, 0}, {165, 350}}
detailsWindowViewIndex = 0
detailsWindowConfigurationsTabIdentifier = log
leftNavSelectedDisplayName = client
AdvancedWindowTabIdentifier = connectingAndDisconnecting
haveDealtWithSparkle1dot5b6 = 1
haveDealtWithOldTunTapPreferences = 1
haveDealtWithOldLoginItem = 1
SUEnableAutomaticChecks = 1
SUScheduledCheckInterval = 86400
SUSendProfileInfo = 1
SULastCheckTime = 2017-10-14 02:59:23 +0000
SULastProfileSubmissionDate = 2017-10-12 12:18:50 +0000
SUHasLaunchedBefore = 1
WebKitDefaultFontSize = 16
WebKitStandardFont = Times

================================================================================

Tunnelblick Log:

2017-10-14 11:04:18 OpenVPN 2.3.18 x86_64-apple-darwin [SSL (OpenSSL)] [LZO] [PKCS11] [MH] [IPv6] built on Sep 26 2017
2017-10-14 11:04:18 library versions: OpenSSL 1.0.2l  25 May 2017, LZO 2.10
2017-10-14 11:04:18 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:1337
2017-10-14 11:04:18 Need hold release from management interface, waiting...
*Tunnelblick: OS X 10.12.6; Tunnelblick 3.7.3beta03 (build 4870); prior version 3.7.2a (build 4851)
2017-10-14 11:04:18 *Tunnelblick: Attempting connection with client using shadow copy; Set nameserver = 769; monitoring connection
2017-10-14 11:04:18 *Tunnelblick: openvpnstart start client.tblk 1337 769 0 1 0 1065264 -ptADGNWradsgnw 2.3.18-openssl-1.0.2l
2017-10-14 11:04:19 *Tunnelblick: openvpnstart log:
     OpenVPN started successfully. Command used to start OpenVPN (one argument per displayed line):
    
          /Applications/Tunnelblick.app/Contents/Resources/openvpn/openvpn-2.3.18-openssl-1.0.2l/openvpn
          --daemon
          --log
          /Library/Application Support/Tunnelblick/Logs/-SUsers-Sxxx-SLibrary-SApplication Support-STunnelblick-SConfigurations-Sclient.tblk-SContents-SResources-Sconfig.ovpn.769_0_1_0_1065264.1337.openvpn.log
          --cd
          /Library/Application Support/Tunnelblick/Users/xxx/client.tblk/Contents/Resources
          --setenv
          IV_GUI_VER
          "net.tunnelblick.tunnelblick 4870 3.7.3beta03 (build 4870)"
          --verb
          3
          --config
          /Library/Application Support/Tunnelblick/Users/xxx/client.tblk/Contents/Resources/config.ovpn
          --verb
          3
          --cd
          /Library/Application Support/Tunnelblick/Users/xxx/client.tblk/Contents/Resources
          --management
          127.0.0.1
          1337
          --management-query-passwords
          --management-hold
          --script-security
          2
          --up
          /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw
          --down
          /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw

2017-10-14 11:04:18 *Tunnelblick: openvpnstart starting OpenVPN
2017-10-14 11:04:19 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:1337
2017-10-14 11:04:19 *Tunnelblick: Established communication with OpenVPN
2017-10-14 11:04:19 *Tunnelblick: Obtained VPN username and password from the Keychain
2017-10-14 11:04:19 MANAGEMENT: CMD 'pid'
2017-10-14 11:04:19 MANAGEMENT: CMD 'state on'
2017-10-14 11:04:19 MANAGEMENT: CMD 'state'
2017-10-14 11:04:19 MANAGEMENT: CMD 'bytecount 1'
2017-10-14 11:04:19 MANAGEMENT: CMD 'hold release'
2017-10-14 11:04:19 MANAGEMENT: CMD 'username "Auth" “xxx”’
2017-10-14 11:04:19 MANAGEMENT: CMD 'password [...]'
2017-10-14 11:04:19 WARNING: --ns-cert-type is DEPRECATED.  Use --remote-cert-tls instead.
2017-10-14 11:04:19 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-10-14 11:04:19 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-10-14 11:04:19 MANAGEMENT: >STATE:1507950259,RESOLVE,,,
2017-10-14 11:04:19 UDPv4 link local: [undef]
2017-10-14 11:04:19 UDPv4 link remote: [AF_INET]xxx.xxx.xxx.xxx:1194
2017-10-14 11:04:19 MANAGEMENT: >STATE:1507950259,WAIT,,,
2017-10-14 11:04:19 MANAGEMENT: >STATE:1507950259,AUTH,,,
2017-10-14 11:04:19 TLS: Initial packet from [AF_INET]xxx.xxx.xxx.xxx:1194, sid=91e928d1 f53ad517
2017-10-14 11:04:19 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
2017-10-14 11:04:20 VERIFY OK: depth=1, C=TW, ST=TW, L=Taipei, O=ASUS, CN=RT-AC66U, emailAddress=m...@myhost.mydomain
2017-10-14 11:04:20 VERIFY OK: nsCertType=SERVER
2017-10-14 11:04:20 VERIFY OK: depth=0, C=TW, ST=TW, L=Taipei, O=ASUS, CN=RT-AC66U, emailAddress=m...@myhost.mydomain
2017-10-14 11:04:22 Data Channel Encrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
2017-10-14 11:04:22 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
2017-10-14 11:04:22 Data Channel Decrypt: Cipher 'AES-128-CBC' initialized with 128 bit key
2017-10-14 11:04:22 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
2017-10-14 11:04:22 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
2017-10-14 11:04:22 [RT-AC66U] Peer Connection Initiated with [AF_INET]xxx.xxx.xxx.xxx:1194
2017-10-14 11:04:23 MANAGEMENT: >STATE:1507950263,GET_CONFIG,,,
2017-10-14 11:04:24 SENT CONTROL [RT-AC66U]: 'PUSH_REQUEST' (status=1)
2017-10-14 11:04:25 PUSH: Received control message: 'PUSH_REPLY,route 192.168.100.0 255.255.255.0 vpn_gateway 500,route 10.8.0.1,topology net30,ping 15,ping-restart 60,ifconfig 10.8.0.6 10.8.0.5'
2017-10-14 11:04:25 OPTIONS IMPORT: timers and/or timeouts modified
2017-10-14 11:04:25 OPTIONS IMPORT: --ifconfig/up options modified
2017-10-14 11:04:25 OPTIONS IMPORT: route options modified
2017-10-14 11:04:25 Opening utun (connect(AF_SYS_CONTROL)): Resource busy
2017-10-14 11:04:25 Opened utun device utun1
2017-10-14 11:04:25 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
2017-10-14 11:04:25 MANAGEMENT: >STATE:1507950265,ASSIGN_IP,,10.8.0.6,
2017-10-14 11:04:25 /sbin/ifconfig utun1 delete
                                        ifconfig: ioctl (SIOCDIFADDR): Can't assign requested address
2017-10-14 11:04:25 NOTE: Tried to delete pre-existing tun/tap instance -- No Problem if failure
2017-10-14 11:04:25 /sbin/ifconfig utun1 10.8.0.6 10.8.0.5 mtu 1500 netmask 255.255.255.255 up
2017-10-14 11:04:25 /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw utun1 1500 1558 10.8.0.6 10.8.0.5 init
                                        **********************************************
                                        Start of output from client.up.tunnelblick.sh
                                        NOTE: No network configuration changes need to be made.
                                        WARNING: Will NOT monitor for other network configuration changes.
                                        WARNING: Will NOT disable IPv6 settings.
                                        DNS servers '172.20.10.1' will be used for DNS queries when the VPN is active
                                        NOTE: The DNS servers do not include any free public DNS servers known to Tunnelblick. This may cause DNS queries to fail or be intercepted or falsified even if they are directed through the VPN. Specify only known public DNS servers or DNS servers located on the VPN network to avoid such problems.
                                        Flushed the DNS cache via dscacheutil
                                        /usr/sbin/discoveryutil not present. Not flushing the DNS cache via discoveryutil
                                        Notified mDNSResponder that the DNS cache was flushed
                                        End of output from client.up.tunnelblick.sh
                                        **********************************************
2017-10-14 11:04:27 *Tunnelblick: No 'connected.sh' script to execute
2017-10-14 11:04:27 MANAGEMENT: >STATE:1507950267,ADD_ROUTES,,,
2017-10-14 11:04:27 /sbin/route add -net 192.168.100.0 10.8.0.5 255.255.255.0
                                        add net 192.168.100.0: gateway 10.8.0.5
2017-10-14 11:04:27 /sbin/route add -net 10.8.0.1 10.8.0.5 255.255.255.255
                                        add net 10.8.0.1: gateway 10.8.0.5
2017-10-14 11:04:27 Initialization Sequence Completed
2017-10-14 11:04:27 MANAGEMENT: >STATE:1507950267,CONNECTED,SUCCESS,10.8.0.6,xxx.xxx.xxx.xxx
2017-10-14 11:04:36 *Tunnelblick: This computer's apparent public IP address (xxx.xxx.xxx.xxx) was unchanged after the connection was made
2017-10-14 11:04:42 *Tunnelblick: Disconnecting; VPN Details… window disconnect button pressed
2017-10-14 11:04:42 *Tunnelblick: No 'pre-disconnect.sh' script to execute
2017-10-14 11:04:42 *Tunnelblick: Disconnecting using 'kill'
2017-10-14 11:04:42 event_wait : Interrupted system call (code=4)
2017-10-14 11:04:42 /sbin/route delete -net 10.8.0.1 10.8.0.5 255.255.255.255
                                        delete net 10.8.0.1: gateway 10.8.0.5
2017-10-14 11:04:42 /sbin/route delete -net 192.168.100.0 10.8.0.5 255.255.255.0
                                        delete net 192.168.100.0: gateway 10.8.0.5
2017-10-14 11:04:42 Closing TUN/TAP interface
2017-10-14 11:04:42 /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw utun1 1500 1558 10.8.0.6 10.8.0.5 init
                                        **********************************************
                                        Start of output from client.down.tunnelblick.sh
                                        WARNING: Not restoring DNS settings because no saved Tunnelblick DNS information was found.
                                        Flushed the DNS cache via dscacheutil
                                        /usr/sbin/discoveryutil not present. Not flushing the DNS cache via discoveryutil
                                        Notified mDNSResponder that the DNS cache was flushed
                                        End of output from client.down.tunnelblick.sh
                                        **********************************************
2017-10-14 11:04:43 SIGTERM[hard,] received, process exiting
2017-10-14 11:04:43 MANAGEMENT: >STATE:1507950283,EXITING,SIGTERM,,
2017-10-14 11:04:43 *Tunnelblick: No 'post-disconnect.sh' script to execute
2017-10-14 11:04:43 *Tunnelblick: Expected disconnection occurred.

================================================================================

"Sanitized" full configuration file

client
dev tun
proto udp
remote xxx.asuscomm.com 1194
float
cipher AES-128-CBC
comp-lzo adaptive
keepalive 15 60
auth-user-pass
ns-cert-type server
<ca>
 [Security-related line(s) omitted]
</ca>
<cert>
 [Security-related line(s) omitted]
</cert>
<key>
 [Security-related line(s) omitted]
</key>
resolv-retry infinite
nobind



================================================================================

ifconfig output:

lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
    options=1203<RXCSUM,TXCSUM,TXSTATUS,SW_TIMESTAMP>
    inet 127.0.0.1 netmask 0xff000000
    inet6 ::1 prefixlen 128
    inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1
    nd6 options=201<PERFORMNUD,DAD>
gif0: flags=8010<POINTOPOINT,MULTICAST> mtu 1280
stf0: flags=0<> mtu 1280
en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
    ether 98:5a:eb:8a:60:7e
    inet6 fe80::c00:de42:c3a4:9c11%en0 prefixlen 64 secured scopeid 0x4
    inet 172.20.10.3 netmask 0xfffffff0 broadcast 172.20.10.15
    nd6 options=201<PERFORMNUD,DAD>
    media: autoselect
    status: active
en1: flags=963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX> mtu 1500
    options=60<TSO4,TSO6>
    ether 72:00:08:cb:d1:80
    media: autoselect <full-duplex>
    status: inactive
en2: flags=963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX> mtu 1500
    options=60<TSO4,TSO6>
    ether 72:00:08:cb:d1:81
    media: autoselect <full-duplex>
    status: inactive
p2p0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 2304
    ether 0a:5a:eb:8a:60:7e
    media: autoselect
    status: inactive
awdl0: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1484
    ether fa:40:07:83:f1:84
    inet6 fe80::f840:7ff:fe83:f184%awdl0 prefixlen 64 scopeid 0x8
    nd6 options=201<PERFORMNUD,DAD>
    media: autoselect
    status: active
bridge0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
    options=63<RXCSUM,TXCSUM,TSO4,TSO6>
    ether 72:00:08:cb:d1:80
    Configuration:
        id 0:0:0:0:0:0 priority 0 hellotime 0 fwddelay 0
        maxage 0 holdcnt 0 proto stp maxaddr 100 timeout 1200
        root id 0:0:0:0:0:0 priority 0 ifcost 0 port 0
        ipfilter disabled flags 0x2
    member: en1 flags=3<LEARNING,DISCOVER>
            ifmaxaddr 0 port 5 priority 0 path cost 0
    member: en2 flags=3<LEARNING,DISCOVER>
            ifmaxaddr 0 port 6 priority 0 path cost 0
    nd6 options=201<PERFORMNUD,DAD>
    media: <unknown type>
    status: inactive
utun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 2000
    inet6 fe80::a214:b795:f3af:36f1%utun0 prefixlen 64 scopeid 0xa
    nd6 options=201<PERFORMNUD,DAD>

================================================================================

Console Log:

2017-10-14 10:35:22 Tunnelblick[1953] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-client' account = 'username'
2017-10-14 10:35:22 Tunnelblick[1953] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-client' account = 'password'
2017-10-14 10:40:00 Tunnelblick[1953] Tunnelblick needs to perform an action that requires administrator authorization.
2017-10-14 10:40:00 Tunnelblick[1953] Beginning installation or repair
2017-10-14 10:40:00 Tunnelblick[1953] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-10-14 10:40:00. 2 arguments: 0x2001
                                            /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk
                                       removed /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk
                                       removed /Library/Application Support/Tunnelblick/Users/xxx/client.tblk
                                       Tunnelblick installer finished without error
2017-10-14 10:40:00 Tunnelblick[1953] Uninstalled configuration file /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk
2017-10-14 10:41:16 Tunnelblick[1953] Converting/Installing /Users/xxx/Downloads/client.ovpn: One or more CR characters have been removed or replaced with LF characters
2017-10-14 10:41:16 Tunnelblick[1953] Converting/Installing /Users/xxx/Downloads/client.ovpn: One or more CR characters have been removed or replaced with LF characters
2017-10-14 10:41:16 Tunnelblick[1953] Converting/Installing /Users/xxx/Downloads/client.ovpn: Converted OpenVPN configuration
2017-10-14 10:41:22 Tunnelblick[1953] localNameFromDisplayName: 'client' is not a known displayName
2017-10-14 10:41:22 Tunnelblick[1953] Tunnelblick needs to perform an action that requires administrator authorization.
2017-10-14 10:41:22 Tunnelblick[1953] Beginning installation or repair
2017-10-14 10:41:22 Tunnelblick[1953] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-10-14 10:41:22. 3 arguments: 0x0001
                                            /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk
                                            /private/var/folders/k2/7nnxcbzd4rvg6h1sr6_n39mw0000gn/T/Tunnelblick-aN5iFz/client.tblk
                                       Copied /private/var/folders/k2/7nnxcbzd4rvg6h1sr6_n39mw0000gn/T/Tunnelblick-aN5iFz/client.tblk
                                           to /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk.temp
                                       Renamed /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk.temp
                                            to /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk
                                       Changed ownership of /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk and its contents from 501:20 to 501:80
                                       Copied /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk
                                           to /Library/Application Support/Tunnelblick/Users/xxx/client.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/xxx/client.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/xxx/client.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/xxx/client.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/xxx/client.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/xxx/client.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/xxx/client.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/xxx/client.tblk/Contents/Resources/config.ovpn
                                       Created secure (shadow) copy of client.tblk
                                       Tunnelblick installer finished without error
2017-10-14 10:42:39 Tunnelblick[1953] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-client' account = 'username'
2017-10-14 10:42:39 Tunnelblick[1953] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-client' account = 'password'
2017-10-14 10:43:39 Tunnelblick[1953] Tunnelblick needs to perform an action that requires administrator authorization.
2017-10-14 10:43:39 Tunnelblick[1953] Beginning installation or repair
2017-10-14 10:43:39 Tunnelblick[1953] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-10-14 10:43:39. 2 arguments: 0x2001
                                            /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk
                                       removed /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk
                                       removed /Library/Application Support/Tunnelblick/Users/xxx/client.tblk
                                       Tunnelblick installer finished without error
2017-10-14 10:43:39 Tunnelblick[1953] Uninstalled configuration file /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk
2017-10-14 10:48:10 Tunnelblick[1953] Converting/Installing /Users/xxx/Downloads/client.ovpn: One or more CR characters have been removed or replaced with LF characters
2017-10-14 10:48:10 Tunnelblick[1953] Converting/Installing /Users/xxx/Downloads/client.ovpn: One or more CR characters have been removed or replaced with LF characters
2017-10-14 10:48:10 Tunnelblick[1953] Converting/Installing /Users/xxx/Downloads/client.ovpn: Converted OpenVPN configuration
2017-10-14 10:48:16 Tunnelblick[1953] localNameFromDisplayName: 'client' is not a known displayName
2017-10-14 10:48:16 Tunnelblick[1953] Tunnelblick needs to perform an action that requires administrator authorization.
2017-10-14 10:48:16 Tunnelblick[1953] Beginning installation or repair
2017-10-14 10:48:16 Tunnelblick[1953] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-10-14 10:48:16. 3 arguments: 0x0001
                                            /Users/raynor/Library/Application Support/Tunnelblick/Configurations/client.tblk
                                            /private/var/folders/k2/7nnxcbzd4rvg6h1sr6_n39mw0000gn/T/Tunnelblick-DAzpX3/client.tblk
                                       Copied /private/var/folders/k2/7nnxcbzd4rvg6h1sr6_n39mw0000gn/T/Tunnelblick-DAzpX3/client.tblk
                                           to /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk.temp
                                       Renamed /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk.temp
                                            to /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk
                                       Changed ownership of /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk and its contents from 501:20 to 501:80
                                       Copied /Users/xxx/Library/Application Support/Tunnelblick/Configurations/client.tblk
                                           to /Library/Application Support/Tunnelblick/Users/xxx/client.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/xxx/client.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/xxx/client.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/xxx/client.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/xxx/client.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/xxx/client.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/xxx/client.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/xxx/client.tblk/Contents/Resources/config.ovpn
                                       Created secure (shadow) copy of client.tblk
                                       Tunnelblick installer finished without error
2017-10-14 10:56:47 Tunnelblick[1953] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-client' account = 'username'
2017-10-14 10:56:47 Tunnelblick[1953] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-client' account = 'password'
2017-10-14 10:58:24 Tunnelblick[1953] Sparkle: Verified appcast signature
2017-10-14 10:58:48 Tunnelblick[1953] Sparkle: Verified appcast signature
2017-10-14 10:59:01 Tunnelblick[1953] Sparkle: Extracting using '/usr/bin/ditto' '-x' '-k' '-' < '/Users/xxx/Library/Caches/net.tunnelblick.tunnelblick/org.sparkle-project.Sparkle/Tunnelblick 4870/Tunnelblick_3.7.3beta03_build_4870.zip' '/Users/xxx/Library/Caches/net.tunnelblick.tunnelblick/org.sparkle-project.Sparkle/Tunnelblick 4870'
2017-10-14 10:59:09 Tunnelblick[1953] updater:willInstallUpdate: Starting cleanup.
2017-10-14 10:59:12 Tunnelblick[1953] pthread_mutex_lock( &unloadKextsMutex ) failed; status = 16, errno = 2
2017-10-14 10:59:12 Tunnelblick[1953] updater:willInstallUpdate: Cleanup finished.
2017-10-14 10:59:12 Tunnelblick[1953] applicationShouldTerminate: termination because of Quit; delayed until 'shutdownTunnelblick' finishes
2017-10-14 10:59:12 Tunnelblick[1953] pthread_mutex_trylock( &cleanupMutex ) failed; status = 16, errno = 3
2017-10-14 10:59:12 Tunnelblick[1953] pthread_mutex_trylock( &cleanupMutex ) failed is normal and expected when Tunnelblick is updated
2017-10-14 10:59:12 Tunnelblick[1953] Finished shutting down Tunnelblick; allowing termination
2017-10-14 10:59:17 Tunnelblick[4572] Tunnelblick: OS X 10.12.6; Tunnelblick 3.7.3beta03 (build 4870)
2017-10-14 10:59:18 Tunnelblick[4572] Need to replace and/or reload 'tunnelblickd':
                                           daemonHashesMatch  = NO
                                           plistHashesMatch   = YES
                                           activePlistMatches = YES
2017-10-14 10:59:22 Tunnelblick[4572] Tunnelblick needs to:
                                         • Complete the update
2017-10-14 10:59:22 Tunnelblick[4572] Beginning installation or repair
2017-10-14 10:59:22 Tunnelblick[4572] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-10-14 10:59:22. 1 arguments: 0x0101
                                       Replaced /Library/LaunchDaemons/net.tunnelblick.tunnelblick.tunnelblickd.plist
                                       Used launchctl to load tunnelblickd
                                       Tunnelblick installer finished without error
2017-10-14 10:59:23 Tunnelblick[4572] Sparkle: ===== Tunnelblick.app =====
2017-10-14 10:59:23 Tunnelblick[4572] Sparkle: Verified appcast signature
2017-10-14 11:00:00 Tunnelblick[4572] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-client' account = 'username'
2017-10-14 11:00:00 Tunnelblick[4572] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-client' account = 'password'
2017-10-14 11:04:19 Tunnelblick[4572] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-client' account = 'username'
2017-10-14 11:04:19 Tunnelblick[4572] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-client' account = 'password'

Please advise, Thanks!

Tunnelblick developer

unread,
Oct 14, 2017, 7:14:13 AM10/14/17
to tunnelblick-discuss
Hi. Please make sure that there is a check in the checkbox for "Route all traffic through the VPN" on the "Settings" tab of the "Configurations" panel of the "VPN Details" window when you have your configuration selected (by clicking on it) in the left side of the same panel.

stephe...@gmail.com

unread,
Oct 21, 2017, 9:10:42 AM10/21/17
to tunnelblick-discuss
I am having the same issue too and have done the same exact test as you with my iphone and using the same config file. I even have the check box checked and no change.

Tunnelblick developer

unread,
Oct 21, 2017, 10:27:54 AM10/21/17
to tunnelblick-discuss
@Stephen - please follow the instructions at Read Before You Post to get the info needed to diagnose problems and then post that info.

stephe...@gmail.com

unread,
Oct 22, 2017, 8:14:54 AM10/22/17
to tunnelblick-discuss
sorry. wasn't looking for help. just making a general statement. if and when I decide to ask for help I I will post whats needed

Dan

unread,
Jun 3, 2018, 11:49:04 AM6/3/18
to tunnelblick-discuss

I have had this and was able to fix it by changing from a tun to tap connection. 

  • To do this, change your line "dev tun" to "dev tap" and make sure you update the port as your VPN server likely uses a different port for tap vs. tun. This will change your IP but in my experience doesn't let me network with the other computers on the network so I have 2 configurations, one if I want to connect to the local network computers and leave my IP alone (tun) and one if I want to route all my browsing through home network but not connect to local machines (tap).

On Saturday, October 14, 2017 at 6:59:11 AM UTC-4, Ray11 wrote:
2017-10-14 11:04:20 VERIFY OK: depth=1, C=TW, ST=TW, L=Taipei, O=ASUS, CN=RT-AC66U, emailAddress=me@myhost.mydomain

2017-10-14 11:04:20 VERIFY OK: nsCertType=SERVER
2017-10-14 11:04:20 VERIFY OK: depth=0, C=TW, ST=TW, L=Taipei, O=ASUS, CN=RT-AC66U, emailAddress=me@myhost.mydomain

Please advise, Thanks!

Tunnelblick developer

unread,
Jun 3, 2018, 1:08:23 PM6/3/18
to tunnelblick-discuss
Changing from "tun" to "tap" on the client and on the server (or vice-versa) will not fix  the problem of the IP address not changing. In the absence of other problems, that's a routing problem, and tun/tap has nothing to do with routing.

The recommended solution to the problem is what I wrote earlier:

Please make sure that there is a check in the checkbox for "Route all traffic through the VPN" on the "Settings" tab of the "Configurations" panel of the "VPN Details" window when you have your configuration selected (by clicking on it) in the left side of the same panel.

Changing from one connection (tap or tun) to another does change to a different configuration on the server. In Dan Breznau's situation I suspect the "tap" server configuration included the routing instructions needed to fix the problem, and the "tun" server configuration did not.

Tap connections are very verbose (they use a lot of bandwidth) and the OpenVPN developers recommend tun connections for almost all situations.

ma...@publisheria.ch

unread,
Jan 14, 2019, 7:19:59 AM1/14/19
to tunnelblick-discuss
I would like to follow up on that. I have the same issue with not changing the IP address (log bellow). I have set the option ""Route all traffic through the VPN" on my Tunnelblick client and on the server (Netgear nighthawk r7000). Here is the strange thing: If you use tunnelblick in my home wifi to connect my office VPN directly, it doesn't work. But if I make a WiFi hotspot with my android phone and use my 4G internet connection, the configs work fine and I get the IP from my workplace.

Any ideas how to fix that?

------ LOG ------

*Tunnelblick: macOS 10.14.2; Tunnelblick 3.7.8 (build 5180); Admin user
git commit 75a15f3fcb6de5a66bb6b7175b720645332ee778


Configuration Home

"Sanitized" condensed configuration file for /Users/mac/Library/Application Support/Tunnelblick/Configurations/Home.tblk:

client
dev tap
proto udp
remote 44.254.93.126 12974
resolv-retry infinite
nobind
persist-key
persist-tun
ca ca.crt
cert client.crt
key client.key
cipher AES-128-CBC
comp-lzo
verb 5


================================================================================

Non-Apple kexts that are loaded:

Index Refs Address            Size       Wired      Name (Version) UUID <Linked Against>
   83    0 0xffffff7f80e70000 0x17f000   0x17f000   at.obdev.nke.LittleSnitch (5210) 0BEBCAD5-9FC2-35B4-A87D-08B14BCB15F5 <8 6 5 3 1>
  160    0 0xffffff7f86195000 0x1d000    0x1d000    com.intel.kext.intelhaxm (6.2.1) 7B6ABC56-699C-3449-A0EC-BEB36C154E3C <8 6 5 3 1>
  177    0 0xffffff7f86221000 0x7000     0x7000     net.tunnelblick.tap (5180.3) 7CADB84E-01B1-3CD4-8FE3-CA4D2BE6C67E <8 6 5 1>

================================================================================

Files in Home.tblk:
      Contents/Resources/cli….crt
      Contents/Resources/ca.crt
      Contents/Resources/config.ovpn
      Contents/Resources/cli….key

================================================================================

Configuration preferences:

-skipWarningThatMayNotConnectInFutureBecauseOfOpenVPNOptions = 1
-routeAllTrafficThroughVpn = 1
-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0
-lastConnectionSucceeded = 1

================================================================================

Wildcard preferences:

-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0

================================================================================

Program preferences:

launchAtNextLogin = 1
tunnelblickVersionHistory = (
    "3.7.8 (build 5180)"
)
statusDisplayNumber = 0
lastLaunchTime = 569096285.323584
lastLanguageAtLaunchWasRTL = 0
connectionWindowDisplayCriteria = showWhenConnecting
maxLogDisplaySize = 102400
lastConnectedDisplayName = Home
keyboardShortcutIndex = 1
updateCheckAutomatically = 1
NSWindow Frame ConnectingWindow = 645 630 389 187 0 0 1680 1027 
detailsWindowFrameVersion = 5180
detailsWindowFrame = {{567, 424}, {920, 468}}
detailsWindowLeftFrame = {{0, 0}, {165, 350}}
detailsWindowViewIndex = 0
detailsWindowConfigurationsTabIdentifier = log
leftNavSelectedDisplayName = Home
AdvancedWindowTabIdentifier = sounds
haveDealtWithOldTunTapPreferences = 1
haveDealtWithOldLoginItem = 1
haveDealtWithAfterDisconnect = 1
SUEnableAutomaticChecks = 1
SUScheduledCheckInterval = 86400
SULastCheckTime = 2019-01-13 18:18:05 +0000
SUHasLaunchedBefore = 1
WebKitDefaultFontSize = 16
WebKitStandardFont = Times

================================================================================

Tunnelblick Log:

*Tunnelblick: macOS 10.14.2; Tunnelblick 3.7.8 (build 5180)
2019-01-14 08:25:17 *Tunnelblick: Attempting connection with Home using shadow copy; Set nameserver = 769; monitoring connection
2019-01-14 08:25:17 *Tunnelblick: openvpnstart start Home.tblk 54249 769 0 1 0 1065842 -ptADGNWradsgnw 2.4.6-openssl-1.0.2q
2019-01-14 08:25:18 *Tunnelblick: openvpnstart log:
     OpenVPN started successfully. Command used to start OpenVPN (one argument per displayed line):
     
          /Applications/Tunnelblick.app/Contents/Resources/openvpn/openvpn-2.4.6-openssl-1.0.2q/openvpn
          --daemon
          --log /Library/Application Support/Tunnelblick/Logs/-SUsers-Smac-SLibrary-SApplication Support-STunnelblick-SConfigurations-SHome.tblk-SContents-SResources-Sconfig.ovpn.769_0_1_0_1065842.54249.openvpn.log
          --cd /Library/Application Support/Tunnelblick/Users/mac/Home.tblk/Contents/Resources
          --setenv IV_GUI_VER "net.tunnelblick.tunnelblick 5180 3.7.8 (build 5180)"
          --verb 3
          --config /Library/Application Support/Tunnelblick/Users/mac/Home.tblk/Contents/Resources/config.ovpn
          --setenv TUNNELBLICK_CONFIG_FOLDER /Library/Application Support/Tunnelblick/Users/mac/Home.tblk/Contents/Resources
          --verb 3
          --cd /Library/Application Support/Tunnelblick/Users/mac/Home.tblk/Contents/Resources
          --management 127.0.0.1 54249 /Library/Application Support/Tunnelblick/jlhomhbipoienlapffbkligecflaldemhmceojbg.mip
          --management-query-passwords
          --management-hold
          --redirect-gateway def1
          --script-security 2
          --up /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -9 -a -d -f -m -w -ptADGNWradsgnw
          --down /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -9 -a -d -f -m -w -ptADGNWradsgnw
          --route-pre-down /Applications/Tunnelblick.app/Contents/Resources/client.route-pre-down.tunnelblick.sh -9 -a -d -f -m -w -ptADGNWradsgnw

2019-01-14 08:25:17 OpenVPN 2.4.6 x86_64-apple-darwin [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [MH/RECVDA] [AEAD] built on Nov 29 2018
2019-01-14 08:25:17 library versions: OpenSSL 1.0.2q  20 Nov 2018, LZO 2.10
2019-01-14 08:25:17 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:54249
2019-01-14 08:25:17 Need hold release from management interface, waiting...
2019-01-14 08:25:17 *Tunnelblick: openvpnstart starting OpenVPN
2019-01-14 08:25:18 *Tunnelblick: Established communication with OpenVPN
2019-01-14 08:25:18 >INFO:OpenVPN Management Interface Version 1 -- type 'help' for more info
2019-01-14 08:25:18 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:54249
2019-01-14 08:25:18 MANAGEMENT: CMD 'pid'
2019-01-14 08:25:18 MANAGEMENT: CMD 'auth-retry interact'
2019-01-14 08:25:18 MANAGEMENT: CMD 'state on'
2019-01-14 08:25:18 MANAGEMENT: CMD 'state'
2019-01-14 08:25:18 MANAGEMENT: CMD 'bytecount 1'
2019-01-14 08:25:18 MANAGEMENT: CMD 'hold release'
2019-01-14 08:25:18 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2019-01-14 08:25:18 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2019-01-14 08:25:18 TCP/UDP: Preserving recently used remote address: [AF_INET]44.254.93.126:12974
2019-01-14 08:25:18 Socket Buffers: R=[786896->786896] S=[9216->9216]
2019-01-14 08:25:18 UDP link local: (not bound)
2019-01-14 08:25:18 UDP link remote: [AF_INET]44.254.93.126:12974
2019-01-14 08:25:18 MANAGEMENT: >STATE:1547450718,WAIT,,,,,,
2019-01-14 08:25:18 MANAGEMENT: >STATE:1547450718,AUTH,,,,,,
2019-01-14 08:25:18 TLS: Initial packet from [AF_INET]44.254.93.126:12974, sid=01b37f01 36f35c88
2019-01-14 08:25:18 VERIFY OK: depth=1, C=TW, ST=TW, L=Taipei, O=home, OU=home, CN=allen, emailAddress=gunfi...@mail2000.com.tw
2019-01-14 08:25:18 VERIFY OK: depth=0, C=TW, ST=TW, O=home, OU=home, CN=allen, emailAddress=gunfi...@mail2000.com.tw
2019-01-14 08:25:18 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
2019-01-14 08:25:18 [allen] Peer Connection Initiated with [AF_INET]44.254.93.126:12974
2019-01-14 08:25:19 MANAGEMENT: >STATE:1547450719,GET_CONFIG,,,,,,
2019-01-14 08:25:19 SENT CONTROL [allen]: 'PUSH_REQUEST' (status=1)
2019-01-14 08:25:19 PUSH: Received control message: 'PUSH_REPLY,route 192.168.1.0 255.255.255.0,route-delay 5,redirect-gateway def1,route-gateway dhcp,ping 10,ping-restart 120'
2019-01-14 08:25:19 OPTIONS IMPORT: timers and/or timeouts modified
2019-01-14 08:25:19 OPTIONS IMPORT: route options modified
2019-01-14 08:25:19 OPTIONS IMPORT: route-related options modified
2019-01-14 08:25:19 Outgoing Data Channel: Cipher 'AES-128-CBC' initialized with 128 bit key
2019-01-14 08:25:19 Outgoing Data Channel: Using 160 bit message hash 'SHA1' for HMAC authentication
2019-01-14 08:25:19 Incoming Data Channel: Cipher 'AES-128-CBC' initialized with 128 bit key
2019-01-14 08:25:19 Incoming Data Channel: Using 160 bit message hash 'SHA1' for HMAC authentication
2019-01-14 08:25:19 OpenVPN ROUTE: OpenVPN needs a gateway parameter for a --route option and no default was specified by either --route-gateway or --ifconfig options
2019-01-14 08:25:19 OpenVPN ROUTE: failed to parse/resolve route for host/network: 192.168.1.0
2019-01-14 08:25:19 TUN/TAP device /dev/tap0 opened
2019-01-14 08:25:19 /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -9 -a -d -f -m -w -ptADGNWradsgnw tap0 1500 1590   init
                                        **********************************************
                                        Start of output from client.up.tunnelblick.sh
                                        Did 'ipconfig set "tap0" DHCP'
                                        Configuring tap DNS via DHCP asynchronously
                                        End of output from client.up.tunnelblick.sh
                                        **********************************************
2019-01-14 08:25:23 Extracted DHCP router address: 192.168.1.1
                                        Sleeping for 0 seconds to wait for DHCP to finish setup.
                                        Retrieved from DHCP/BOOTP packet: name server(s) [ 192.168.1.1 ], search domain(s) [  ] and SMB server(s) [  ] and using default domain name [ openvpn ]
                                        Not aggregating ServerAddresses because running on macOS 10.6 or higher
                                        Setting search domains to 'openvpn' because the search domains were not set manually (or are allowed to be changed) and 'Prepend domain name to search domains' was not selected
2019-01-14 08:25:26 /sbin/route add -net 44.254.93.126 192.168.1.1 255.255.255.255
                                        add net 44.254.93.126: gateway 192.168.1.1
2019-01-14 08:25:26 /sbin/route add -net 0.0.0.0 192.168.1.1 128.0.0.0
                                        add net 0.0.0.0: gateway 192.168.1.1
2019-01-14 08:25:26 /sbin/route add -net 128.0.0.0 192.168.1.1 128.0.0.0
                                        add net 128.0.0.0: gateway 192.168.1.1
2019-01-14 08:25:26 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
2019-01-14 08:25:26 Initialization Sequence Completed
2019-01-14 08:25:26 MANAGEMENT: >STATE:1547450726,CONNECTED,SUCCESS,,44.254.93.126,12974,,
2019-01-14 08:25:26 *Tunnelblick: No 'connected.sh' script to execute
                                        Saved the DNS and SMB configurations so they can be restored
                                        Did not change DNS ServerAddresses setting of '192.168.1.1' (but re-set it)
                                        Changed DNS SearchDomains setting from '' to 'openvpn'
                                        Changed DNS DomainName setting from '' to 'openvpn'
                                        Did not change SMB NetBIOSName setting of ''
                                        Did not change SMB Workgroup setting of ''
                                        Did not change SMB WINSAddresses setting of ''
                                        DNS servers '192.168.1.1' will be used for DNS queries when the VPN is active
                                        NOTE: The DNS servers do not include any free public DNS servers known to Tunnelblick. This may cause DNS queries to fail or be intercepted or falsified even if they are directed through the VPN. Specify only known public DNS servers or DNS servers located on the VPN network to avoid such problems.
                                        Flushed the DNS cache via dscacheutil
                                        /usr/sbin/discoveryutil not present. Not flushing the DNS cache via discoveryutil
                                        Notified mDNSResponder that the DNS cache was flushed
                                        Not notifying mDNSResponderHelper that the DNS cache was flushed because it is not running
                                        Setting up to monitor system configuration with process-network-changes
2019-01-14 08:25:30 *Tunnelblick process-network-changes: A system configuration change was ignored
2019-01-14 08:25:31 *Tunnelblick: This computer's apparent public IP address (212.51.155.2) was unchanged after the connection was made
2019-01-14 08:25:35 *Tunnelblick: Disconnecting; VPN Details… window disconnect button pressed
2019-01-14 08:25:35 *Tunnelblick: No 'pre-disconnect.sh' script to execute
2019-01-14 08:25:35 *Tunnelblick: Disconnecting using 'kill'
2019-01-14 08:25:35 event_wait : Interrupted system call (code=4)
2019-01-14 08:25:35 /Applications/Tunnelblick.app/Contents/Resources/client.route-pre-down.tunnelblick.sh -9 -a -d -f -m -w -ptADGNWradsgnw tap0 1500 1590   init
                                        **********************************************
                                        Start of output from client.route-pre-down.tunnelblick.sh
                                        WARNING: Ignoring change of Network Primary Service from 9B3C5EE3-852F-4F63-8252-2F069065C6DC to   RestoreIpv6Services : 
                                        9B3C5EE3-852F-4F63-8252-2F069065C6DC
                                        Cancelled monitoring of system configuration changes
                                        Released the DHCP lease via ipconfig set "tap0" NONE.
                                        End of output from client.route-pre-down.tunnelblick.sh
                                        **********************************************
2019-01-14 08:25:35 /sbin/route delete -net 44.254.93.126 192.168.1.1 255.255.255.255
                                        delete net 44.254.93.126: gateway 192.168.1.1
2019-01-14 08:25:35 /sbin/route delete -net 0.0.0.0 192.168.1.1 128.0.0.0
                                        delete net 0.0.0.0: gateway 192.168.1.1
2019-01-14 08:25:35 /sbin/route delete -net 128.0.0.0 192.168.1.1 128.0.0.0
                                        delete net 128.0.0.0: gateway 192.168.1.1
2019-01-14 08:25:35 Closing TUN/TAP interface
2019-01-14 08:25:35 /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -9 -a -d -f -m -w -ptADGNWradsgnw tap0 1500 1590   init
                                        **********************************************
                                        Start of output from client.down.tunnelblick.sh
                                        Restored the DNS and SMB configurations
                                        Flushed the DNS cache via dscacheutil
                                        /usr/sbin/discoveryutil not present. Not flushing the DNS cache via discoveryutil
                                        Notified mDNSResponder that the DNS cache was flushed
                                        Not notifying mDNSResponderHelper that the DNS cache was flushed because it is not running
                                        /Library/Application Support/Tunnelblick/expect-disconnect/ALL does not exist
                                        End of output from client.down.tunnelblick.sh
                                        **********************************************
2019-01-14 08:25:36 SIGTERM[hard,] received, process exiting
2019-01-14 08:25:36 MANAGEMENT: >STATE:1547450736,EXITING,SIGTERM,,,,,
2019-01-14 08:25:36 *Tunnelblick: No 'post-disconnect.sh' script to execute
2019-01-14 08:25:36 *Tunnelblick: Expected disconnection occurred.

================================================================================

"Sanitized" full configuration file

client
dev tap
proto udp
remote 44.254.93.126 12974
resolv-retry infinite
nobind
persist-key
persist-tun
ca ca.crt
cert client.crt
key client.key
cipher AES-128-CBC
comp-lzo
verb 5



================================================================================

Network services:

An asterisk (*) denotes that a network service is disabled.
HideMyAss
USB Modem Port
LPSS Serial Adapter (1)
LPSS Serial Adapter (2)
Display Ethernet
Display FireWire
Wi-Fi
Bluetooth PAN
Thunderbolt Bridge
Apple USB Ethernet Adapter
iPhone USB

Wi-Fi Power (en0): On

================================================================================

ifconfig output:

lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
options=1203<RXCSUM,TXCSUM,TXSTATUS,SW_TIMESTAMP>
inet 127.0.0.1 netmask 0xff000000 
inet6 ::1 prefixlen 128 
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1 
nd6 options=201<PERFORMNUD,DAD>
gif0: flags=8010<POINTOPOINT,MULTICAST> mtu 1280
stf0: flags=0<> mtu 1280
XHC0: flags=0<> mtu 0
XHC20: flags=0<> mtu 0
XHC1: flags=0<> mtu 0
en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
ether 78:4f:43:96:ed:e7 
inet6 fe80::100d:7ee1:d320:d967%en0 prefixlen 64 secured scopeid 0x8 
inet 192.168.1.24 netmask 0xffffff00 broadcast 192.168.1.255
nd6 options=201<PERFORMNUD,DAD>
media: autoselect
status: active
p2p0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 2304
ether 0a:4f:43:96:ed:e7 
media: autoselect
status: inactive
awdl0: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1484
ether 32:55:9f:a4:80:7a 
inet6 fe80::3055:9fff:fea4:807a%awdl0 prefixlen 64 scopeid 0xa 
nd6 options=201<PERFORMNUD,DAD>
media: autoselect
status: active
en3: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=60<TSO4,TSO6>
ether 1a:00:e4:d0:b4:01 
media: autoselect <full-duplex>
status: inactive
en1: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=60<TSO4,TSO6>
ether 1a:00:e4:d0:b4:00 
media: autoselect <full-duplex>
status: inactive
en4: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=60<TSO4,TSO6>
ether 1a:00:e4:d0:b4:05 
media: autoselect <full-duplex>
status: inactive
en2: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=60<TSO4,TSO6>
ether 1a:00:e4:d0:b4:04 
media: autoselect <full-duplex>
status: inactive
bridge0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=63<RXCSUM,TXCSUM,TSO4,TSO6>
ether 1a:00:e4:d0:b4:00 
Configuration:
id 0:0:0:0:0:0 priority 0 hellotime 0 fwddelay 0
maxage 0 holdcnt 0 proto stp maxaddr 100 timeout 1200
root id 0:0:0:0:0:0 priority 0 ifcost 0 port 0
ipfilter disabled flags 0x2
member: en1 flags=3<LEARNING,DISCOVER>
        ifmaxaddr 0 port 12 priority 0 path cost 0
member: en2 flags=3<LEARNING,DISCOVER>
        ifmaxaddr 0 port 14 priority 0 path cost 0
member: en3 flags=3<LEARNING,DISCOVER>
        ifmaxaddr 0 port 11 priority 0 path cost 0
member: en4 flags=3<LEARNING,DISCOVER>
        ifmaxaddr 0 port 13 priority 0 path cost 0
nd6 options=201<PERFORMNUD,DAD>
media: <unknown type>
status: inactive
utun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 2000
inet6 fe80::3fd2:c9b2:31a2:18b0%utun0 prefixlen 64 scopeid 0x10 
nd6 options=201<PERFORMNUD,DAD>
en5: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
ether ac:de:48:00:11:22 
inet6 fe80::aede:48ff:fe00:1122%en5 prefixlen 64 scopeid 0x7 
nd6 options=201<PERFORMNUD,DAD>
media: autoselect
status: active

================================================================================

Console Log:

2019-01-14 08:13:16 Tunnelblick[771] Set 'expect disconnect 1 -SLibrary-SApplication Support-STunnelblick-SUsers-Smac-SHome-Dtblk-SContents-SResources'
2019-01-14 08:13:17 Tunnelblick[771] startDisconnectingUserKnows: while already disconnecting 'Home'; OpenVPN state = 'DISCONNECTING'
2019-01-14 08:13:17 Tunnelblick[771] Set 'expect disconnect 1 -SLibrary-SApplication Support-STunnelblick-SUsers-Smac-SHome-Dtblk-SContents-SResources'
2019-01-14 08:25:17 Tunnelblick[771] Cleared 'expect disconnect 0 -SLibrary-SApplication Support-STunnelblick-SUsers-Smac-SHome-Dtblk-SContents-SResources'
2019-01-14 08:25:35 Tunnelblick[771] Set 'expect disconnect 1 -SLibrary-SApplication Support-STunnelblick-SUsers-Smac-SHome-Dtblk-SContents-SResources'

Tunnelblick developer

unread,
Jan 14, 2019, 7:28:59 AM1/14/19
to tunnelblick-discuss
These errors from OpenVPN point to the problem:

2019-01-14 08:25:19 OpenVPN ROUTE: OpenVPN needs a gateway parameter for a --route option and no default was specified by either --route-gateway or --ifconfig options
2019-01-14 08:25:19 OpenVPN ROUTE: failed to parse/resolve route for host/network: 192.168.1.0

ma...@publisheria.ch

unread,
Jan 14, 2019, 8:06:29 AM1/14/19
to tunnelblick-discuss
OK, thanks I'll look into that. But how can it be that the same config works if I'm using a different WiFi network? 

Tunnelblick developer

unread,
Jan 14, 2019, 8:16:01 AM1/14/19
to tunnelblick-discuss
Because different networks have different properties (MTU limits, for example), and they provide different networking parameters to your computer via DHCP.

ma...@publisheria.ch

unread,
Jan 14, 2019, 12:03:26 PM1/14/19
to tunnelblick-discuss
I'm not 100 pro sure that the following lines really point in the direction of my issue. If also have the same msgs if I connect thru my 4G hotspot and the connection works if I use the hotspot. Any other ideas?

2019-01-14 17:57:49 OpenVPN ROUTE: OpenVPN needs a gateway parameter for a --route option and no default was specified by either --route-gateway or --ifconfig options
2019-01-14 17:57:49 OpenVPN ROUTE: failed to parse/resolve route for host/network: 192.168.1.0

Thanks

Tunnelblick developer

unread,
Jan 14, 2019, 12:12:44 PM1/14/19
to tunnelblick-discuss
Contact Netgear support.

drew...@gmail.com

unread,
Dec 5, 2019, 2:05:53 PM12/5/19
to tunnelblick-discuss
You saved me! Even though you suggested the opposite, you prompted me to the issue! The configuration file that was generated from netgear was set to dev tap on default. Once I switched it to dev tun and set the correct port, it worked! Thanks again.

Emmanuele Battista

unread,
Jan 12, 2020, 11:24:56 AM1/12/20
to tunnelblick-discuss
I have the same problem! Could you please send me the conf file you received from netgear support?
Thanks

Emmanuele Battista

unread,
Jan 15, 2020, 2:44:28 AM1/15/20
to tunnelblick-discuss
Dear drew...@gmail.com,

I have the same problem as yours! Could you please send me the conf file you received from netgear support? You can contact me privately.

Many Thanks!!!!!

Il giorno giovedì 5 dicembre 2019 20:05:53 UTC+1, drew...@gmail.com ha scritto:
Reply all
Reply to author
Forward
0 new messages