Can not connect to internet after disconnecting from tunnelblick

2,589 views
Skip to first unread message

Ben Wyss

unread,
Jan 31, 2017, 11:04:14 PM1/31/17
to tunnelblick-discuss
On my office network I can connect and disconnect and everything is fine, When I am on my home network, I am not able to connect to internet when tunnelblick is disconnected. When I connect I have internet access.

Tunnelblick developer

unread,
Jan 31, 2017, 11:07:14 PM1/31/17
to tunnelblick-discuss, bmw...@gmail.com
Please follow the instructions at Read Before You Post to get the info needed to diagnose problems and then post that info.

Ben Wyss

unread,
Jan 31, 2017, 11:40:05 PM1/31/17
to tunnelblick-discuss
Tunnelblick 3.7.0 (build 4790) on Mac OSX 10.11.6 
Here are some logs:

Flushed the DNS cache via dscacheutil

                                        /usr/sbin/discoveryutil not present. Not flushing the DNS cache via discoveryutil

                                        Notified mDNSResponder that the DNS cache was flushed

                                        Setting up to monitor system configuration with process-network-changes

                                        End of output from client.up.tunnelblick.sh

                                        **********************************************

2017-01-31 20:18:42 *Tunnelblick: No 'connected.sh' script to execute

2017-01-31 20:18:42 *Tunnelblick: Could not determine this computer's apparent public IP address before the connection was completed

2017-01-31 20:18:42 Initialization Sequence Completed

2017-01-31 20:18:42 MANAGEMENT: >STATE:1485922722,CONNECTED,SUCCESS,myipaddess.18,52.40.1.184

2017-01-31 20:18:47 *Tunnelblick process-network-changes: A system configuration change was ignored

2017-01-31 20:19:30 *Tunnelblick: Disconnecting; VPN Details… window disconnect button pressed

2017-01-31 20:19:30 *Tunnelblick: No 'pre-disconnect.sh' script to execute

2017-01-31 20:19:30 *Tunnelblick: Disconnecting using 'kill'

2017-01-31 20:19:30 event_wait : Interrupted system call (code=4)

2017-01-31 20:19:30 /sbin/route delete -net 192.167.255.1 192.167.255.17 255.255.255.255

                                        delete net 192.168.255.1: gateway 192.167.255.17

2017-01-31 20:19:30 /sbin/route delete -net 52.40.1.184 192.167.0.1 255.255.255.255

                                        delete net 52.40.1.184: gateway 192.167.0.1

2017-01-31 20:19:30 /sbin/route delete -net 0.0.0.0 192.167.255.17 128.0.0.0

                                        delete net 0.0.0.0: gateway 192.167.255.17

2017-01-31 20:19:30 /sbin/route delete -net 128.0.0.0 192.167.255.17 128.0.0.0

                                        delete net 128.0.0.0: gateway 192.178.255.17

2017-01-31 20:19:30 Closing TUN/TAP interface

2017-01-31 20:19:30 /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -9 -d -f -m -r -w -ptADGNWradsgnw utun0 1500 1541 192.168.255.18 192.168.255.17 init

                                        **********************************************

                                        Start of output from client.down.tunnelblick.sh

                                        Cancelled monitoring of system configuration changes

                                        Restored the DNS and SMB configurations

                                        Flushed the DNS cache via dscacheutil

                                        /usr/sbin/discoveryutil not present. Not flushing the DNS cache via discoveryutil

                                        Notified mDNSResponder that the DNS cache was flushed

                                        Resetting primary interface 'en0' via networksetup -setairportpower en0 off/on...

                                        End of output from client.down.tunnelblick.sh

                                        **********************************************

2017-01-31 20:19:33 SIGTERM[hard,] received, process exiting

2017-01-31 20:19:33 MANAGEMENT: >STATE:1485922773,EXITING,SIGTERM,,

2017-01-31 20:19:34 *Tunnelblick: No 'post-disconnect.sh' script to execute

2017-01-31 20:19:34 *Tunnelblick: Expected disconnection occurred.

Tunnelblick developer

unread,
Feb 1, 2017, 5:44:55 AM2/1/17
to tunnelblick-discuss
"some logs" doesn't help.

Please follow the instructions at Read Before You Post to get the info needed to diagnose problems and then post that info.

ultr...@gmail.com

unread,
Mar 29, 2017, 4:11:10 PM3/29/17
to tunnelblick-discuss
Hi Developer,
I have the same problem as the OP. I connect to the VPN and everything seems to work fine, then when I disconnect my internet is lost and I have either to turn AirPort off and on or restart the computer to get it back. It happens with all VPN configurations. Please  find a copy of the Diagnostics Info obtained following the instructions.
Thank you.


*Tunnelblick: OS X 10.6.8; Tunnelblick 3.5.12 (build 4270.4800); prior version 3.4beta24 (build 3806); Admin user

Configuration Belgium-udp

"Sanitized" condensed configuration file for /Users/Josep/Library/Application Support/Tunnelblick/Configurations/Belgium-udp.tblk:

client
dev tun
proto udp
remote vleu-be1-ovpn-udp.ivacy.net 53
persist-key
persist-tun
ca ca.crt
tls-auth Wdc.key 1
cipher AES-256-CBC
comp-lzo
verb 1
mute 20
route-method exe
route-delay 2
route 0.0.0.0 0.0.0.0
auth-user-pass
auth-retry interact
explicit-exit-notify 2
ifconfig-nowarn
auth-nocache


================================================================================

"Sanitized" full configuration file

client
dev tun
proto udp
remote vleu-be1-ovpn-udp.ivacy.net 53
persist-key
persist-tun
ca ca.crt
tls-auth Wdc.key 1
cipher AES-256-CBC
comp-lzo
verb 1
mute 20
route-method exe
route-delay 2
route 0.0.0.0 0.0.0.0
auth-user-pass
auth-retry interact
explicit-exit-notify 2
ifconfig-nowarn
auth-nocache



================================================================================

There are no unusual files in Belgium-udp.tblk

================================================================================

Configuration preferences:

-keychainHasUsername = 1
-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0
-lastConnectionSucceeded = 1

================================================================================

Wildcard preferences:

-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 1

================================================================================

Program preferences:

launchAtNextLogin = 1
notOKToCheckThatIPAddressDidNotChangeAfterConnection = 1
askedUserIfOKToCheckThatIPAddressDidNotChangeAfterConnection = 1
tunnelblickVersionHistory = (
    "3.5.12 (build 4270.4800)",
    "3.4beta24 (build 3806)"
)
lastLaunchTime = 512509366.165934
showConnectedDurations = 1
connectionWindowDisplayCriteria = showWhenConnecting
maxLogDisplaySize = 102400
lastConnectedDisplayName = Belgium-udp
keyboardShortcutIndex = 1
updateCheckAutomatically = 0
updateSendProfileInfo = 0
NSWindow Frame SettingsSheetWindow = 303 354 829 424 0 0 1280 778
NSWindow Frame ConnectingWindow = 412 360 412 297 0 0 1280 778
detailsWindowFrameVersion = 4270.4800
detailsWindowFrame = {{160, 232}, {900, 468}}
detailsWindowLeftFrame = {{0, 0}, {163, 350}}
leftNavSelectedDisplayName = Belgium-udp
haveDealtWithSparkle1dot5b6 = 1
haveDealtWithOldTunTapPreferences = 1
haveDealtWithOldLoginItem = 1
SUEnableAutomaticChecks = 0
SUFeedURL = https://www.tunnelblick.net/appcast-s.rss
SUScheduledCheckInterval = 86400
SUSendProfileInfo = 0
SULastCheckTime = 2014-04-29 17:21:16 +0100
SUHasLaunchedBefore = 1
WebKitDefaultFontSize = 16
WebKitStandardFont = Times

================================================================================

Tunnelblick Log:

2017-03-29 20:46:43 *Tunnelblick: OS X 10.6.8; Tunnelblick 3.5.12 (build 4270.4800); prior version 3.4beta24 (build 3806)
2017-03-29 20:46:44 *Tunnelblick: Attempting connection with Belgium-udp using shadow copy; Set nameserver = 1; monitoring connection
2017-03-29 20:46:44 *Tunnelblick: openvpnstart start Belgium-udp.tblk 1337 1 0 1 0 16688 -ptADGNWradsgnw 2.3.11
2017-03-29 20:46:45 *Tunnelblick: openvpnstart log:
     OpenVPN started successfully. Command used to start OpenVPN (one argument per displayed line):
    
          /Applications/Tunnelblick.app/Contents/Resources/openvpn/openvpn-2.3.11/openvpn
          --daemon
          --log
          /Library/Application Support/Tunnelblick/Logs/-SUsers-SJosep-SLibrary-SApplication Support-STunnelblick-SConfigurations-SBelgium--udp.tblk-SContents-SResources-Sconfig.ovpn.1_0_1_0_16688.1337.openvpn.log
          --cd
          /Library/Application Support/Tunnelblick/Users/Josep/Belgium-udp.tblk/Contents/Resources
          --config
          /Library/Application Support/Tunnelblick/Users/Josep/Belgium-udp.tblk/Contents/Resources/config.ovpn
          --cd
          /Library/Application Support/Tunnelblick/Users/Josep/Belgium-udp.tblk/Contents/Resources
          --management
          127.0.0.1
          1337
          --management-query-passwords
          --management-hold
          --script-security
          2
          --up
          /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -d -f -m -w -ptADGNWradsgnw
          --down
          /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -d -f -m -w -ptADGNWradsgnw

2017-03-29 20:46:44 *Tunnelblick: openvpnstart starting OpenVPN
2017-03-29 20:46:45 *Tunnelblick: Established communication with OpenVPN
2017-03-29 20:46:45 OpenVPN 2.3.11 x86_64-apple-darwin [SSL (OpenSSL)] [LZO] [PKCS11] [MH] [IPv6] built on Jan 29 2017
2017-03-29 20:46:45 library versions: OpenSSL 1.0.2k  26 Jan 2017, LZO 2.08
2017-03-29 20:46:51 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-03-29 20:46:51 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-03-29 20:46:51 Control Channel Authentication: using 'Wdc.key' as a OpenVPN static key file
2017-03-29 20:46:51 UDPv4 link local (bound): [undef]
2017-03-29 20:46:51 UDPv4 link remote: [AF_INET]172.111.197.130:53
2017-03-29 20:46:52 [PureVPN] Peer Connection Initiated with [AF_INET]172.111.197.130:53
2017-03-29 20:46:55 Opened utun device utun0
2017-03-29 20:46:55 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
2017-03-29 20:46:55 /sbin/ifconfig utun0 delete
                                        ifconfig: ioctl (SIOCDIFADDR): Can't assign requested address
2017-03-29 20:46:55 NOTE: Tried to delete pre-existing tun/tap instance -- No Problem if failure
2017-03-29 20:46:55 /sbin/ifconfig utun0 172.111.197.234 172.111.197.234 netmask 255.255.255.224 mtu 1500 up
                                        add net 172.111.197.224: gateway 172.111.197.234
2017-03-29 20:46:55 /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -d -f -m -w -ptADGNWradsgnw utun0 1500 1558 172.111.197.234 255.255.255.224 init
                                        **********************************************
                                        Start of output from client.up.tunnelblick.sh
                                        Retrieved from OpenVPN: name server(s) [ 172.111.197.131 8.8.4.4 ], search domain(s) [  ] and SMB server(s) [  ] and using default domain name [ openvpn ]
                                        Not aggregating ServerAddresses because running on OS X 10.6 or higher
                                        Setting search domains to 'openvpn' because running under OS X 10.6 or higher and the search domains were not set manually and 'Prepend domain name to search domains' was not selected
                                        Saved the DNS and SMB configurations so they can be restored
                                        Changed DNS ServerAddresses setting from '192.168.0.1' to '172.111.197.131 8.8.4.4'
                                        Changed DNS SearchDomains setting from '' to 'openvpn'
                                        Changed DNS DomainName setting from 'Home' to 'openvpn'
                                        Did not change SMB NetBIOSName setting of ''
                                        Did not change SMB Workgroup setting of ''
                                        Did not change SMB WINSAddresses setting of ''
                                        DNS servers '172.111.197.131 8.8.4.4' will be used for DNS queries when the VPN is active
                                        The DNS servers include one or more free public DNS servers known to Tunnelblick and one or more DNS servers not known to Tunnelblick. If used, the DNS servers not known to Tunnelblick may cause DNS queries to fail or be intercepted or falsified even if they are directed through the VPN. Specify only known public DNS servers or DNS servers located on the VPN network to avoid such problems.

                                        Flushed the DNS cache via dscacheutil
                                        /usr/sbin/discoveryutil not present. Not flushing the DNS cache via discoveryutil
                                        Notified mDNSResponder that the DNS cache was flushed
                                        Setting up to monitor system configuration with process-network-changes
                                        End of output from client.up.tunnelblick.sh
                                        **********************************************
                                        add net 172.111.197.130: gateway 192.168.0.1
                                        add net 0.0.0.0: gateway 172.111.197.225
                                        add net 128.0.0.0: gateway 172.111.197.225
                                        route: writing to routing socket: File exists
                                        add net 0.0.0.0: gateway 172.111.197.225: File exists
2017-03-29 20:47:01 Initialization Sequence Completed
2017-03-29 20:47:01 *Tunnelblick: No 'connected.sh' script to execute
2017-03-29 20:47:01 *Tunnelblick: Could not determine this computer's apparent public IP address before the connection was completed
2017-03-29 20:47:03 *Tunnelblick process-network-changes: A system configuration change was ignored
2017-03-29 20:47:34 *Tunnelblick: Disconnecting; VPN Details… window disconnect button pressed
2017-03-29 20:47:34 *Tunnelblick: Disconnecting using 'kill'
2017-03-29 20:47:35 event_wait : Interrupted system call (code=4)
2017-03-29 20:47:35 SIGTERM received, sending exit notification to peer
                                        delete net 0.0.0.0: gateway 172.111.197.225
                                        delete net 172.111.197.130: gateway 192.168.0.1
                                        delete net 0.0.0.0: gateway 172.111.197.225
                                        delete net 128.0.0.0: gateway 172.111.197.225
2017-03-29 20:47:37 /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -d -f -m -w -ptADGNWradsgnw utun0 1500 1558 172.111.197.234 255.255.255.224 init

                                        **********************************************
                                        Start of output from client.down.tunnelblick.sh
                                        Cancelled monitoring of system configuration changes
                                        Restored the DNS and SMB configurations
                                        Flushed the DNS cache via dscacheutil
                                        /usr/sbin/discoveryutil not present. Not flushing the DNS cache via discoveryutil
                                        Notified mDNSResponder that the DNS cache was flushed
                                        End of output from client.down.tunnelblick.sh
                                        **********************************************
2017-03-29 20:47:37 SIGTERM[soft,exit-with-notification] received, process exiting
2017-03-29 20:47:38 *Tunnelblick: No 'post-disconnect.sh' script to execute
2017-03-29 20:47:38 *Tunnelblick: Expected disconnection occurred.

================================================================================

ifconfig output:

lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
    inet6 ::1 prefixlen 128
    inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1
    inet 127.0.0.1 netmask 0xff000000
gif0: flags=8010<POINTOPOINT,MULTICAST> mtu 1280
stf0: flags=0<> mtu 1280
en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
    ether c4:2c:03:15:15:67
    media: autoselect (none)
    status: inactive
en1: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
    ether d8:a2:5e:8e:ef:52
    inet 192.168.0.2 netmask 0xffffff00 broadcast 192.168.0.255
    media: autoselect
    status: active
fw0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 4078
    lladdr d8:a2:5e:ff:fe:df:be:54
    media: autoselect <full-duplex>
    status: inactive
vmnet1: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
    ether 00:50:56:c0:00:01
    inet 172.16.179.1 netmask 0xffffff00 broadcast 172.16.179.255
vmnet8: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
    ether 00:50:56:c0:00:08
    inet 192.168.149.1 netmask 0xffffff00 broadcast 192.168.149.255

================================================================================

Console Log:

2017-03-29 20:42:45 Tunnelblick[288] Set program update feedURL to https://www.tunnelblick.net/appcast-s.rss
2017-03-29 20:46:43 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.100000 seconds...
2017-03-29 20:46:43 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.200000 seconds...
2017-03-29 20:46:43 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.400000 seconds...
2017-03-29 20:46:43 tunnelblickd[302] Status = 0 from tunnelblick-helper command 'compareShadowCopy Belgium-udp'
2017-03-29 20:46:44 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.100000 seconds...
2017-03-29 20:46:44 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.200000 seconds...
2017-03-29 20:46:44 tunnelblickd[302] Status = 0 from tunnelblick-helper command 'printSanitizedConfigurationFile Belgium-udp.tblk 0'
2017-03-29 20:46:44 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.100000 seconds...
2017-03-29 20:46:44 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.200000 seconds...
2017-03-29 20:46:44 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.400000 seconds...
2017-03-29 20:46:45 tunnelblickd[302] Status = 0 from tunnelblick-helper command 'start Belgium-udp.tblk 1337 1 0 1 0 16688 -ptADGNWradsgnw 2.3.11'
2017-03-29 20:46:45 Tunnelblick[288] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-Belgium-udp' account = 'username'
2017-03-29 20:46:45 Tunnelblick[288] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-Belgium-udp' account = 'username'
2017-03-29 20:46:51 Tunnelblick[288] Can't find Keychain item to delete for service = 'Tunnelblick-Auth-Belgium-udp' account = 'password' because it does not exist
2017-03-29 20:47:01 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.100000 seconds...
2017-03-29 20:47:01 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.200000 seconds...
2017-03-29 20:47:01 tunnelblickd[302] Status = 0 from tunnelblick-helper command 'connected Belgium-udp.tblk 1'
2017-03-29 20:47:16 Tunnelblick[288] currentIPInfo(Name): IP address info could not be fetched within 67108864.0 seconds; the error was 'Error Domain=NSURLErrorDomain Code=-1200 UserInfo=0x36af10 "An SSL error has occurred and a secure connection to the server cannot be made." Underlying Error=(Error Domain=kCFErrorDomainCFNetwork Code=-1200 UserInfo=0x5e22d0 "An SSL error has occurred and a secure connection to the server cannot be made.")'; the response was '(null)'
2017-03-29 20:47:34 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.100000 seconds...
2017-03-29 20:47:35 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.200000 seconds...
2017-03-29 20:47:35 tunnelblickd[456] Status = 0 from tunnelblick-helper command 'kill 309'
2017-03-29 20:47:38 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.100000 seconds...
2017-03-29 20:47:38 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.200000 seconds...
2017-03-29 20:47:38 tunnelblickd[456] Status = 0 from tunnelblick-helper command 'postDisconnect Belgium-udp.tblk 1'
2017-03-29 20:48:16 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.100000 seconds...
2017-03-29 20:48:16 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.200000 seconds...
2017-03-29 20:48:17 tunnelblickd[546] Status = 0 from tunnelblick-helper command 'printSanitizedConfigurationFile Belgium-udp.tblk 0'
2017-03-29 20:50:37 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.100000 seconds...
2017-03-29 20:50:37 Tunnelblick[288] runTunnelblickd: no data available from tunnelblickd socket; sleeping 0.200000 seconds...
2017-03-29 20:50:37 tunnelblickd[568] Status = 0 from tunnelblick-helper command 'printSanitizedConfigurationFile Belgium-udp.tblk 0'

================================================================================

Non-Apple kexts that are loaded:

Index Refs Address    Size       Wired      Name (Version) <Linked Against>
  105    0 0x1ab5000  0x5000     0x4000     com.parallels.kext.Pvsnet (2.2) <5 4 3 1>
  129    0 0x6e1a7000 0xd2000    0xd1000    com.vmware.kext.vmx86 (3.1.4) <11 5 4 3 1>
  130    0 0x59381000 0xc000     0xb000     com.vmware.kext.vmci (3.1.4) <5 4 3 1>
  131    0 0x59364000 0x6000     0x5000     com.vmware.kext.vmioplug (3.1.4) <34 29 5 4 3 1>
  132    0 0x5935a000 0xa000     0x9000     com.vmware.kext.vmnet (3.1.4) <5 4 3 1>

Tunnelblick developer

unread,
Mar 29, 2017, 4:17:41 PM3/29/17
to tunnelblick-discuss
Put a check in the "Reset primary interface after disconnecting" checkbox on the "Settings" tab. Be sure to select the configuration(s) that you want to make the change to before checking or unchecking the box.

ultr...@gmail.com

unread,
Mar 29, 2017, 6:44:44 PM3/29/17
to tunnelblick-discuss
Thank you!
Reply all
Reply to author
Forward
0 new messages