Waiting for server response

179 views
Skip to first unread message

Charles Looker

unread,
Jul 9, 2023, 4:15:07 PM7/9/23
to tunnelblick-discuss
The status remains "waiting for server response".
I sometime get a message box saying "There was a problem checking this computer's apparent publicIP address".
In the Settings window, the option "Check if apparent public IP address changed after connecting@ is disabled.
In the following Diagnostic Info (sorry, I can't see how to attach it as a file):
  • The version number of Tunnelblick does not appear to be correct - in the info tab it says: 4.0.0beta06 (build 5860).
  • I have redacted the IP address of the server
  • I have removed repeating lines from the console output - the last eleven lines shown repeat every 30 seconds.
Thank you for any help you can give.

*Tunnelblick: macOS 13.4.1 (22F82); Tunnelblick 3.8.8b (build 5777); Admin user
git commit f31bd6a342f68953ea12d0a389c7c10aab1c4f18 + uncommitted changes:
?? ../third_party/sources/IOUserEthernetController.h
The Tunnelblick.app process is not being translated (arm64)
System Integrity Protection is enabled
Model: Mac14,5

Configuration client

"Sanitized" condensed configuration file for /Users/charl/Library/Application Support/Tunnelblick/Configurations/client.tblk:

remote xxx.xx.x.xx 1194
float
nobind
proto udp
dev tun
sndbuf 0
rcvbuf 0
keepalive 10 30
comp-lzo yes
auth-user-pass
client
auth SHA1
ignore-unknown-option cipher data-ciphers
cipher AES-128-CBC
data-ciphers AES-128-CBC
remote-cert-tls server
<ca>
[Security-related line(s) omitted]
</ca>
<cert>
[Security-related line(s) omitted]
</cert>
<key>
[Security-related line(s) omitted]
</key>


================================================================================

Files in client.tblk:
      Contents/Resources/config.ovpn

================================================================================

Tunnelblick Kext Policy Data:

net.tunnelblick.tun|Z2SG5H3HC8|Jonathan Bullard|0|32
net.tunnelblick.tap|Z2SG5H3HC8|Jonathan Bullard|0|32

================================================================================

Configuration preferences:

-keychainHasUsernameAndPassword = 1
-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0
-loginWindowSecurityTokenCheckboxIsChecked = 0
-lastConnectionSucceeded = 0

================================================================================

Wildcard preferences:

-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0

================================================================================

Program preferences:

launchAtNextLogin = 1
tunnelblickVersionHistory = (
    "3.8.8b (build 5777)"
)
lastLaunchTime = 710621665.901625
lastLanguageAtLaunchWasRTL = 0
connectionWindowDisplayCriteria = showWhenConnecting
maxLogDisplaySize = 102400
lastConnectedDisplayName = client (1)
keyboardShortcutIndex = 1
updateCheckAutomatically = 1
NSWindow Frame ConnectingWindow = 561 561 389 217 0 0 1512 944
detailsWindowFrameVersion = 5777
detailsWindowFrame = {{296, 331}, {920, 522}}
detailsWindowLeftFrame = {{0, 0}, {167, 402}}
detailsWindowViewIndex = 0
detailsWindowConfigurationsTabIdentifier = log
leftNavSelectedDisplayName = client
haveDealtWithOldTunTapPreferences = 1
haveDealtWithAlwaysShowLoginWindow = 1
haveDealtWithOldLoginItem = 1
haveDealtWithAfterDisconnect = 1
SUEnableAutomaticChecks = 1
SUScheduledCheckInterval = 86400
SULastCheckTime = 2023-07-09 18:54:26 +0000
SUHasLaunchedBefore = 1

================================================================================

Forced preferences:

(None)

================================================================================

Deployed forced preferences:

(None)

================================================================================

Tunnelblick Log:

2023-07-09 19:55:36.316928 *Tunnelblick: macOS 13.4.1 (22F82); Tunnelblick 3.8.8b (build 5777)
2023-07-09 19:55:36.997293 *Tunnelblick: Attempting connection with client using shadow copy; Set nameserver = 769; monitoring connection
2023-07-09 19:55:36.997477 *Tunnelblick: openvpnstart start client.tblk 49342 769 0 1 0 34652464 -ptADGNWradsgnw 2.5.9-openssl-1.1.1u <password>
2023-07-09 19:55:37.017802 *Tunnelblick: openvpnstart starting OpenVPN
2023-07-09 19:55:37.311557 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2023-07-09 19:55:37.311842 OpenVPN 2.5.9 x86_64-apple-darwin [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [MH/RECVDA] [AEAD] built on Jun  3 2023
2023-07-09 19:55:37.311859 library versions: OpenSSL 1.1.1u  30 May 2023, LZO 2.10
2023-07-09 19:55:37.312731 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:49342
2023-07-09 19:55:37.312748 Need hold release from management interface, waiting...
2023-07-09 19:55:37.622645 *Tunnelblick: openvpnstart log:
     OpenVPN started successfully.
     Command used to start OpenVPN (one argument per displayed line):
          /Applications/Tunnelblick.app/Contents/Resources/openvpn/openvpn-2.5.9-openssl-1.1.1u/openvpn
          --daemon
          --log /Library/Application Support/Tunnelblick/Logs/-SUsers-Scharl-SLibrary-SApplication Support-STunnelblick-SConfigurations-Sclient.tblk-SContents-SResources-Sconfig.ovpn.769_0_1_0_34652464.49342.openvpn.log
          --cd /Library/Application Support/Tunnelblick/Users/charl/client.tblk/Contents/Resources
          --machine-readable-output
          --setenv IV_GUI_VER "net.tunnelblick.tunnelblick 5777 3.8.8b (build 5777)"
          --verb 3
          --config /Library/Application Support/Tunnelblick/Users/charl/client.tblk/Contents/Resources/config.ovpn
          --setenv TUNNELBLICK_CONFIG_FOLDER /Library/Application Support/Tunnelblick/Users/charl/client.tblk/Contents/Resources
          --verb 3
          --cd /Library/Application Support/Tunnelblick/Users/charl/client.tblk/Contents/Resources
          --management 127.0.0.1 49342 /Library/Application Support/Tunnelblick/Mips/client.tblk.mip
          --management-query-passwords
          --management-hold
          --script-security 2
          --route-up /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw
          --down /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw
2023-07-09 19:55:37.625388 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:49342
2023-07-09 19:55:37.647417 *Tunnelblick: Established communication with OpenVPN
2023-07-09 19:55:37.647533 MANAGEMENT: CMD 'pid'
2023-07-09 19:55:37.647632 MANAGEMENT: CMD 'auth-retry interact'
2023-07-09 19:55:37.647680 MANAGEMENT: CMD 'state on'
2023-07-09 19:55:37.647713 MANAGEMENT: CMD 'state'
2023-07-09 19:55:37.647773 MANAGEMENT: CMD 'bytecount 1'
2023-07-09 19:55:37.647954 *Tunnelblick: >INFO:OpenVPN Management Interface Version 3 -- type 'help' for more info
2023-07-09 19:55:37.648292 MANAGEMENT: CMD 'hold release'
2023-07-09 19:55:37.652744 *Tunnelblick: Obtained VPN username and password from the Keychain
2023-07-09 19:55:37.653473 MANAGEMENT: CMD 'username "Auth" "charles"'
2023-07-09 19:55:37.653648 MANAGEMENT: CMD 'password [...]'
2023-07-09 19:55:37.653856 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2023-07-09 19:55:37.655597 TCP/UDP: Preserving recently used remote address: [AF_INET]100.95.0.11:1194
2023-07-09 19:55:37.655755 Socket Buffers: R=[786896->786896] S=[9216->9216]
2023-07-09 19:55:37.655788 UDP link local: (not bound)
2023-07-09 19:55:37.655802 UDP link remote: [AF_INET]xxx.xx.x.xx:1194
2023-07-09 19:55:37.655828 MANAGEMENT: >STATE:1688928937,WAIT,,,,,,
2023-07-09 19:56:07.664718 [UNDEF] Inactivity timeout (--ping-restart), restarting
2023-07-09 19:56:07.665613 SIGUSR1[soft,ping-restart] received, process restarting
2023-07-09 19:56:07.665668 MANAGEMENT: >STATE:1688928967,RECONNECTING,ping-restart,,,,,
2023-07-09 19:56:07.686655 MANAGEMENT: CMD 'hold release'
2023-07-09 19:56:07.686834 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2023-07-09 19:56:07.687539 TCP/UDP: Preserving recently used remote address: [AF_INET]100.95.0.11:1194
2023-07-09 19:56:07.687665 Socket Buffers: R=[786896->786896] S=[9216->9216]
2023-07-09 19:56:07.687684 UDP link local: (not bound)
2023-07-09 19:56:07.687695 UDP link remote: [AF_INET]xxx.xx.x.xx:1194
2023-07-09 19:56:07.687721 MANAGEMENT: >STATE:1688928967,WAIT,,,,,,
2023-07-09 19:56:07.692783 MANAGEMENT: CMD 'hold release'
2023-07-09 19:56:37.962362 [UNDEF] Inactivity timeout (--ping-restart), restarting
2023-07-09 19:56:37.962980 SIGUSR1[soft,ping-restart] received, process restarting
2023-07-09 19:56:37.963046 MANAGEMENT: >STATE:1688928997,RECONNECTING,ping-restart,,,,,
2023-07-09 19:56:37.986717 MANAGEMENT: CMD 'hold release'
2023-07-09 19:56:37.986921 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2023-07-09 19:56:37.987721 TCP/UDP: Preserving recently used remote address: [AF_INET]100.95.0.11:1194
2023-07-09 19:56:37.987848 Socket Buffers: R=[786896->786896] S=[9216->9216]
2023-07-09 19:56:37.987869 UDP link local: (not bound)
2023-07-09 19:56:37.987880 UDP link remote: [AF_INET]xxx.xx.x.xx:1194
2023-07-09 19:56:37.987904 MANAGEMENT: >STATE:1688928997,WAIT,,,,,,
2023-07-09 19:56:37.988305 MANAGEMENT: CMD 'hold release'
2023-07-09 19:57:07.699919 [UNDEF] Inactivity timeout (--ping-restart), restarting
2023-07-09 19:57:07.700256 SIGUSR1[soft,ping-restart] received, process restarting
2023-07-09 19:57:07.700295 MANAGEMENT: >STATE:1688929027,RECONNECTING,ping-restart,,,,,
2023-07-09 19:57:07.722512 MANAGEMENT: CMD 'hold release'
2023-07-09 19:57:07.722673 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2023-07-09 19:57:07.723244 TCP/UDP: Preserving recently used remote address: [AF_INET]100.95.0.11:1194
2023-07-09 19:57:07.723354 Socket Buffers: R=[786896->786896] S=[9216->9216]
2023-07-09 19:57:07.723378 UDP link local: (not bound)
2023-07-09 19:57:07.723389 UDP link remote: [AF_INET]xxx.xx.x.xx:1194
2023-07-09 19:57:07.723415 MANAGEMENT: >STATE:1688929027,WAIT,,,,,,
2023-07-09 19:57:07.723795 MANAGEMENT: CMD 'hold release'
2023-07-09 19:57:37.810295 [UNDEF] Inactivity timeout (--ping-restart), restarting
2023-07-09 19:57:37.810729 SIGUSR1[soft,ping-restart] received, process restarting
2023-07-09 19:57:37.810784 MANAGEMENT: >STATE:1688929057,RECONNECTING,ping-restart,,,,,
2023-07-09 19:57:37.835408 MANAGEMENT: CMD 'hold release'
2023-07-09 19:57:37.835568 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2023-07-09 19:57:37.836175 TCP/UDP: Preserving recently used remote address: [AF_INET]100.95.0.11:1194
2023-07-09 19:57:37.836286 Socket Buffers: R=[786896->786896] S=[9216->9216]
2023-07-09 19:57:37.836305 UDP link local: (not bound)
2023-07-09 19:57:37.836318 UDP link remote: [AF_INET]xxx.xx.x.xx:1194
2023-07-09 19:57:37.836344 MANAGEMENT: >STATE:1688929057,WAIT,,,,,,
2023-07-09 19:57:37.836722 MANAGEMENT: CMD 'hold release'

================================================================================

Down log:

11:04:06 *Tunnelblick:  **********************************************
11:04:06 *Tunnelblick:  Start of output from client.down.tunnelblick.sh
11:04:07 *Tunnelblick:  WARNING: Not restoring network settings because no saved Tunnelblick DNS information was found.
11:04:07 *Tunnelblick:  Flushed the DNS cache with dscacheutil -flushcache
11:04:07 *Tunnelblick:  Notified mDNSResponder that the DNS cache was flushed
11:04:07 *Tunnelblick:  End of output from client.down.tunnelblick.sh
11:04:07 *Tunnelblick:  **********************************************

================================================================================

Previous down log:

(Not found)
================================================================================

Network services:

An asterisk (*) denotes that a network service is disabled.
Thunderbolt Bridge
Wi-Fi

Wi-Fi Power (en0): On

================================================================================

ifconfig output:

lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
options=1203<RXCSUM,TXCSUM,TXSTATUS,SW_TIMESTAMP>
inet 127.0.0.1 netmask 0xff000000
inet6 ::1 prefixlen 128
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1
nd6 options=201<PERFORMNUD,DAD>
gif0: flags=8010<POINTOPOINT,MULTICAST> mtu 1280
stf0: flags=0<> mtu 1280
anpi2: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether f6:4e:7c:f8:71:b9
inet6 fe80::f44e:7cff:fef8:71b9%anpi2 prefixlen 64 scopeid 0x4
nd6 options=201<PERFORMNUD,DAD>
media: none
status: inactive
anpi0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether f6:4e:7c:f8:71:b7
inet6 fe80::f44e:7cff:fef8:71b7%anpi0 prefixlen 64 scopeid 0x5
nd6 options=201<PERFORMNUD,DAD>
media: none
status: inactive
anpi1: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether f6:4e:7c:f8:71:b8
inet6 fe80::f44e:7cff:fef8:71b8%anpi1 prefixlen 64 scopeid 0x6
nd6 options=201<PERFORMNUD,DAD>
media: none
status: inactive
en4: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether f6:4e:7c:f8:71:97
nd6 options=201<PERFORMNUD,DAD>
media: none
status: inactive
en5: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether f6:4e:7c:f8:71:98
nd6 options=201<PERFORMNUD,DAD>
media: none
status: inactive
en6: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether f6:4e:7c:f8:71:99
nd6 options=201<PERFORMNUD,DAD>
media: none
status: inactive
en1: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=460<TSO4,TSO6,CHANNEL_IO>
ether 36:9e:b7:0f:f8:40
media: autoselect <full-duplex>
status: inactive
en2: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=460<TSO4,TSO6,CHANNEL_IO>
ether 36:9e:b7:0f:f8:44
media: autoselect <full-duplex>
status: inactive
en3: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=460<TSO4,TSO6,CHANNEL_IO>
ether 36:9e:b7:0f:f8:48
media: autoselect <full-duplex>
status: inactive
bridge0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=63<RXCSUM,TXCSUM,TSO4,TSO6>
ether 36:9e:b7:0f:f8:40
Configuration:
id 0:0:0:0:0:0 priority 0 hellotime 0 fwddelay 0
maxage 0 holdcnt 0 proto stp maxaddr 100 timeout 1200
root id 0:0:0:0:0:0 priority 0 ifcost 0 port 0
ipfilter disabled flags 0x0
member: en1 flags=3<LEARNING,DISCOVER>
        ifmaxaddr 0 port 10 priority 0 path cost 0
member: en2 flags=3<LEARNING,DISCOVER>
        ifmaxaddr 0 port 11 priority 0 path cost 0
member: en3 flags=3<LEARNING,DISCOVER>
        ifmaxaddr 0 port 12 priority 0 path cost 0
nd6 options=201<PERFORMNUD,DAD>
media: <unknown type>
status: inactive
ap1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=6463<RXCSUM,TXCSUM,TSO4,TSO6,CHANNEL_IO,PARTIAL_CSUM,ZEROINVERT_CSUM>
ether 7e:e9:1e:7c:cb:67
inet6 fe80::7ce9:1eff:fe7c:cb67%ap1 prefixlen 64 scopeid 0xe
nd6 options=201<PERFORMNUD,DAD>
media: autoselect (<unknown type>)
status: inactive
en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=6463<RXCSUM,TXCSUM,TSO4,TSO6,CHANNEL_IO,PARTIAL_CSUM,ZEROINVERT_CSUM>
ether 5c:e9:1e:7c:cb:67
inet6 fe80::1c15:a480:5521:409c%en0 prefixlen 64 secured scopeid 0xf
inet 172.20.10.5 netmask 0xfffffff0 broadcast 172.20.10.15
nd6 options=201<PERFORMNUD,DAD>
media: autoselect
status: active
awdl0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=6463<RXCSUM,TXCSUM,TSO4,TSO6,CHANNEL_IO,PARTIAL_CSUM,ZEROINVERT_CSUM>
ether ea:6c:6e:ad:83:eb
inet6 fe80::e86c:6eff:fead:83eb%awdl0 prefixlen 64 scopeid 0x10
nd6 options=201<PERFORMNUD,DAD>
media: autoselect
status: active
llw0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether ea:6c:6e:ad:83:eb
inet6 fe80::e86c:6eff:fead:83eb%llw0 prefixlen 64 scopeid 0x11
nd6 options=201<PERFORMNUD,DAD>
media: autoselect
status: inactive
utun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1380
inet6 fe80::61b9:ceb4:86fc:7f8e%utun0 prefixlen 64 scopeid 0x12
nd6 options=201<PERFORMNUD,DAD>
utun1: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 2000
inet6 fe80::579e:b478:b30a:c1d8%utun1 prefixlen 64 scopeid 0x13
nd6 options=201<PERFORMNUD,DAD>
utun2: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1000
inet6 fe80::ce81:b1c:bd2c:69e%utun2 prefixlen 64 scopeid 0x14
nd6 options=201<PERFORMNUD,DAD>

================================================================================

Non-Apple kexts that are loaded:

Index Refs Address            Size       Wired      Name (Version) UUID <Linked Against>

================================================================================

Quit Log:

2023-07-09 19:54:13.263896 applicationShouldTerminate: termination because of Quit; delayed until 'shutdownTunnelblick' finishes)
2023-07-09 19:54:13.267247 shutDownTunnelblick: started.
2023-07-09 19:54:13.268615 shutDownTunnelblick: Starting cleanup.
2023-07-09 19:54:13.269226 cleanup: Entering cleanup
2023-07-09 19:54:13.275691 synchronized user defaults
2023-07-09 19:54:14.180511 shutDownTunnelblick: Cleanup finished.
2023-07-09 19:54:14.181803 Finished shutting down Tunnelblick; allowing termination

================================================================================

Traces Log:


================================================================================

Console Log:


Tunnelblick developer

unread,
Jul 9, 2023, 4:44:39 PM7/9/23
to tunnelblick-discuss
I have no idea why you see "4.0.0beta06 (build 5860)" in the Info tab. I've never heard of such a thing and cannot imagine how it could happen. Can you reproduce it?

Similarly, I have never heard of getting "There was a problem checking this computer's apparent public IP address" when Tunnelblick is not checking the IP address. Perhaps you received that message in the past and IP address checking was subsequently disabled.

Waiting for server response" can be caused by anything interfering with the connection to the VPN server: a hardware or software firewall, a misbehaving VPN server, etc. A problem with the server's certificates can also cause this problem.

However, given the occasional "problem checking this computer's apparent public IP address", my guess is that the server is malfunctioning: either it is down and not responding to anything, or there is a problem with the security certificates in your configuration.

Have you contacted your VPN service provider?




Charles Looker

unread,
Jul 10, 2023, 10:17:44 AM7/10/23
to tunnelblick-discuss
Sorry, I should have said something about the server side.

I have OpenVPN set up on an Asus ZenWiFI XT8 router.  I used a config file generated by the router, so I would expect the certificates to be correct.  I have checked that the IP address and port number are correct in the config file.

I conducted my tests while connected to the Personal Hotspot on my iPhone if that makes any difference.I will investigate further what's happening with version numbers.  Is there any situation where the 4.0.0 would be any different from the 3.8.8 concerning this sort of error.

I appreciate that this is most probably a server problem, but is there anything in the diagnostic info that I should be looking for to find out what kind of problem it is?

Tunnelblick developer

unread,
Jul 10, 2023, 10:34:10 AM7/10/23
to tunnelblick-discuss
There's nothing in 4.0 vs. 3.8.8 that would affect this, and I agree that certificates should not be a problem because the configuration came from the router.

Unfortunately, there's no real info available for "waiting for server response", because, well, there's no response, so nothing to indicate what happened or where it happened.

Could it have anything to do with the network your connecting from?

You could try some ASUS forums or their tech support. Or reset your router to factory settings, update its firmware, and try again.

Reply all
Reply to author
Forward
0 new messages