Hello,
Here's my configuration and log file:
Client.conf:
client
dev tun
proto udp
remote XXX.XXXXXX.XXX XXXXX
resolv-retry infinite
nobind
user nobody
group nobody
persist-key
persist-tun
ca ca.crt
cert cert.crt
key key.key
ns-cert-type server
tls-auth ta.key 1
cipher AES-256-CBC
comp-lzo
verb 3
Log file:
2011-01-31 16:33:05 *Tunnelblick: OS X 10.6.5; Tunnelblick 3.1.3
(build 2190.2305); OpenVPN 2.1.4
2011-01-31 16:33:07 *Tunnelblick: Attempting connection with
XXXXXXXXXXX; Set nameserver = 3; monitoring connection
2011-01-31 16:33:07 *Tunnelblick: /Applications/Tunnelblick.app/
Contents/Resources/openvpnstart start XXXXXXXXXXX.tblk
2011-01-31 16:33:07 *Tunnelblick: openvpnstart: /Applications/
Tunnelblick.app/Contents/Resources/openvpn --cd /Users/martijn/Library/
Application Support/Tunnelblick/Configurations/XXXXXXXXXXX.tblk/
Contents/Resources --daemon --management 127.0.0.1 XXXX --config /
Users/martijn/Library/Application Support/Tunnelblick/Configurations/
XXXXXXXXXXX.tblk/Contents/Resources/config.ovpn --log /Library/
Application Support/Tunnelblick/Logs/-SUsers-Smartijn-SLibrary-
SApplication Support-STunnelblick-SConfigurations-SXXXXXXXXXXX.tblk-
SContents-SResources-Sconfig.ovpn.X_X_X_X_XX.XXXX.openvpn.log --
management-query-passwords --management-hold --script-security 2 --up /
Applications/Tunnelblick.app/Contents/Resources/
client.up.tunnelblick.sh -m -w -d --plugin /Applications/
Tunnelblick.app/Contents/Resources/openvpn-down-root.so /Applications/
Tunnelblick.app/Contents/Resources/
client.down.tunnelblick.sh -m -w -d
--up-restart
2011-01-31 16:33:08 OpenVPN 2.1.4 i386-apple-darwin10.5.0 [SSL] [LZO2]
[PKCS11] built on Dec 9 2010
2011-01-31 16:33:08 MANAGEMENT: TCP Socket listening on 127.0.0.1:XXXX
2011-01-31 16:33:08 Need hold release from management interface,
waiting...
2011-01-31 16:33:08 MANAGEMENT: Client connected from 127.0.0.1:XXXX
2011-01-31 16:33:08 MANAGEMENT: CMD 'pid'
2011-01-31 16:33:08 MANAGEMENT: CMD 'state on'
2011-01-31 16:33:08 MANAGEMENT: CMD 'state'
2011-01-31 16:33:08 MANAGEMENT: CMD 'hold release'
2011-01-31 16:33:08 NOTE: the current --script-security setting may
allow this configuration to call user-defined scripts
2011-01-31 16:33:08 PLUGIN_INIT: POST /Applications/Tunnelblick.app/
Contents/Resources/openvpn-down-root.so '[/Applications/
Tunnelblick.app/Contents/Resources/openvpn-down-root.so] [/
Applications/Tunnelblick.app/Contents/Resources/
client.down.tunnelblick.sh] [-m] [-w] [-d]' intercepted=PLUGIN_UP|
PLUGIN_DOWN
2011-01-31 16:33:08 Control Channel Authentication: using 'ta.key' as
a OpenVPN static key file
2011-01-31 16:33:08 Outgoing Control Channel Authentication: Using 160
bit message hash 'SHA1' for HMAC authentication
2011-01-31 16:33:08 Incoming Control Channel Authentication: Using 160
bit message hash 'SHA1' for HMAC authentication
2011-01-31 16:33:08 LZO compression initialized
2011-01-31 16:33:08 Control Channel MTU parms [ L:1558 D:166 EF:66 EB:
0 ET:0 EL:0 ]
2011-01-31 16:33:08 Socket Buffers: R=[42080->65536] S=[9216->65536]
2011-01-31 16:33:08 MANAGEMENT: >STATE:1296487988,RESOLVE,,,
2011-01-31 16:33:08 Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:
135 ET:0 EL:0 AF:3/1 ]
2011-01-31 16:33:08 Local Options hash (VER=V4): '9e7066d2'
2011-01-31 16:33:08 Expected Remote Options hash (VER=V4): '162b04de'
2011-01-31 16:33:08 NOTE: UID/GID downgrade will be delayed because of
--client, --pull, or --up-delay
2011-01-31 16:33:08 UDPv4 link local: [undef]
2011-01-31 16:33:08 UDPv4 link remote: XXX.XXX.XXX.XXX:XXX
2011-01-31 16:33:08 MANAGEMENT: >STATE:1296487988,WAIT,,,
2011-01-31 16:33:08 MANAGEMENT: >STATE:1296487988,AUTH,,,
2011-01-31 16:33:08 TLS: Initial packet from XXX.XXX.XXX.XXX:XXX,
sid=6f76576c 1f654707
2011-01-31 16:33:08 VERIFY OK: depth=1, /C=NL/ST=NH/L=XXXXXXXXXXX/
O=XXXXXXXXXXX/CN=XXXXXXXXXXX_CA/emailAddress=XXXXX...@XXXXXXX.XXX
2011-01-31 16:33:08 VERIFY OK: nsCertType=SERVER
2011-01-31 16:33:08 VERIFY OK: depth=0, /C=NL/ST=NH/L=XXXXXXXXXXX/
O=XXXXXXXXXXX/CN=server/emailAddress=XXXXX...@XXXXXXX.XXX
2011-01-31 16:33:08 Data Channel Encrypt: Cipher 'AES-256-CBC'
initialized with 256 bit key
2011-01-31 16:33:08 Data Channel Encrypt: Using 160 bit message hash
'SHA1' for HMAC authentication
2011-01-31 16:33:08 Data Channel Decrypt: Cipher 'AES-256-CBC'
initialized with 256 bit key
2011-01-31 16:33:08 Data Channel Decrypt: Using 160 bit message hash
'SHA1' for HMAC authentication
2011-01-31 16:33:08 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-
AES256-SHA, 2048 bit RSA
2011-01-31 16:33:08 [server] Peer Connection Initiated with
XXX.XXX.XXX.XXX:XXX
2011-01-31 16:33:09 MANAGEMENT: >STATE:1296487989,GET_CONFIG,,,
2011-01-31 16:33:10 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
2011-01-31 16:33:10 PUSH: Received control message:
'PUSH_REPLY,redirect-gateway def1 bypass-dhcp,dhcp-option DNS
XXX.XXX.XXX.XXX,dhcp-option DNS XXX.XXX.XXX.XXX,dhcp-option DOMAIN
XXXXXXXXX.XXX,route XXX.XXX.XXX.XXX XXX.XXX.XXX.XXX,topology
net30,ping 10,ping-restart 120,ifconfig XXX.XXX.XXX.XXX
XXX.XXX.XXX.XXX'
2011-01-31 16:33:10 OPTIONS IMPORT: timers and/or timeouts modified
2011-01-31 16:33:10 OPTIONS IMPORT: --ifconfig/up options modified
2011-01-31 16:33:10 OPTIONS IMPORT: route options modified
2011-01-31 16:33:10 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option
options modified
2011-01-31 16:33:10 ROUTE default_gateway=XXX.XXX.XXX.XXX
2011-01-31 16:33:10 TUN/TAP device /dev/tun0 opened
2011-01-31 16:33:10 MANAGEMENT: >STATE:
1296487990,ASSIGN_IP,,XXX.XXX.XXX.XXX,
2011-01-31 16:33:10 /sbin/ifconfig tun0 delete
2011-01-31 16:33:10 NOTE: Tried to delete pre-existing tun/tap
instance -- No Problem if failure
2011-01-31 16:33:10 /sbin/ifconfig tun0 XXX.XXX.XXX.XXX
XXX.XXX.XXX.XXX mtu 1500 netmask XXX.XXX.XXX.XXX up
2011-01-31 16:33:10 PLUGIN_CALL: POST /Applications/Tunnelblick.app/
Contents/Resources/
openvpn-down-root.so/PLUGIN_UP status=0
2011-01-31 16:33:10 /Applications/Tunnelblick.app/Contents/Resources/
client.up.tunnelblick.sh -m -w -d tun0 1500 1558 XXX.XXX.XXX.XXX
XXX.XXX.XXX.XXX init
No such key
2011-01-31 16:33:10 /sbin/route add -net XXX.XXX.XXX.XXX
XXX.XXX.XXX.XXX XXX.XXX.XXX.XXX
route:
writing to routing socket:
File exists
add net XXX.XXX.XXX.XXX:
gateway XXX.XXX.XXX.XXX: File exists
2011-01-31 16:33:10 /sbin/route add -net XXX.XXX.XXX.XXX
XXX.XXX.XXX.XXX XXX.XXX.XXX.XXX
add net XXX.XXX.XXX.XXX:
gateway XXX.XXX.XXX.XXX
2011-01-31 16:33:10 /sbin/route add -net XXX.XXX.XXX.XXX
XXX.XXX.XXX.XXX XXX.XXX.XXX.XXX
add net XXX.XXX.XXX.XXX:
gateway XXX.XXX.XXX.XXX
2011-01-31 16:33:10 MANAGEMENT: >STATE:1296487990,ADD_ROUTES,,,
2011-01-31 16:33:10 /sbin/route add -net XXX.XXX.XXX.XXX
XXX.XXX.XXX.XXX XXX.XXX.XXX.XXX
add net XXX.XXX.XXX.XXX:
gateway XXX.XXX.XXX.XXX
2011-01-31 16:33:10 GID set to nobody
2011-01-31 16:33:10 UID set to nobody
2011-01-31 16:33:10 Initialization Sequence Completed
2011-01-31 16:33:10 MANAGEMENT: >STATE:
1296487990,CONNECTED,SUCCESS,XXX.XXX.XXX.XXX,XXX.XXX.XXX.XXX
2011-01-31 16:33:10 *Tunnelblick
client.up.tunnelblick.sh: Up to two
'No such key' warnings are normal and may be ignored
2011-01-31 16:33:10 *Tunnelblick
client.up.tunnelblick.sh: Saved the
DNS and WINS configurations for later use
2011-01-31 16:33:10 *Tunnelblick
client.up.tunnelblick.sh: Set up to
monitor system configuration with leasewatch
2011-01-31 16:33:10 *Tunnelblick: Flushed the DNS cache
2011-01-31 16:33:15 *Tunnelblick leasewatch: A system configuration
change was ignored because it was not relevant
2011-01-31 16:33:18 event_wait : Interrupted system call (code=4)
2011-01-31 16:33:18 TCP/UDP: Closing socket
2011-01-31 16:33:18 /sbin/route delete -net XXX.XXX.XXX.XXX
XXX.XXX.XXX.XXX XXX.XXX.XXX.XXX
route: must be root to alter
routing table
2011-01-31 16:33:18 ERROR: OS X route delete command failed: external
program exited with error status: 77
2011-01-31 16:33:18 /sbin/route delete -net XXX.XXX.XXX.XXX
XXX.XXX.XXX.XXX XXX.XXX.XXX.XXX
route: must be root to alter
routing table
2011-01-31 16:33:18 ERROR: OS X route delete command failed: external
program exited with error status: 77
2011-01-31 16:33:18 /sbin/route delete -net XXX.XXX.XXX.XXX
XXX.XXX.XXX.XXX XXX.XXX.XXX.XXX
route: must be root to alter
routing table
2011-01-31 16:33:18 ERROR: OS X route delete command failed: external
program exited with error status: 77
2011-01-31 16:33:18 /sbin/route delete -net XXX.XXX.XXX.XXX
XXX.XXX.XXX.XXX XXX.XXX.XXX.XXX
route: must be root to alter
routing table
2011-01-31 16:33:18 ERROR: OS X route delete command failed: external
program exited with error status: 77
2011-01-31 16:33:18 Closing TUN/TAP interface
2011-01-31 16:33:19 PLUGIN_CALL: POST /Applications/Tunnelblick.app/
Contents/Resources/
openvpn-down-root.so/PLUGIN_DOWN status=0
2011-01-31 16:33:19 PLUGIN_CLOSE: /Applications/Tunnelblick.app/
Contents/Resources/openvpn-down-root.so
2011-01-31 16:33:19 SIGTERM[hard,] received, process exiting
2011-01-31 16:33:19 MANAGEMENT: >STATE:1296487999,EXITING,SIGTERM,,
2011-01-31 16:33:19 *Tunnelblick
client.down.tunnelblick.sh: Cancelled
monitoring of system configuration changes
2011-01-31 16:33:19 *Tunnelblick
client.down.tunnelblick.sh: Restored
the DNS and WINS configurations
2011-01-31 16:33:19 *Tunnelblick: Flushed the DNS cache