Auto Connect

93 views
Skip to first unread message

Ali Afshany

unread,
Aug 26, 2021, 2:59:43 PM8/26/21
to tunnelblick-discuss

hi there
thanks for this amazing app.
i work with it everyday, and i face an annoying issue.
well i am from iran and our internet is not that HQ.
i face connection drop usually and although every auto connect checkbox is checked but i still have to disconnect and reconnect it to be able to surf the web.
it seems when this drop happens, tunnelblick is not able to detect this network drop and remains falsely connected.

i hope you have understood what i mean.
sorry for my bad english.

best regards

Tunnelblick developer

unread,
Aug 26, 2021, 3:08:50 PM8/26/21
to tunnelblick-discuss
Does the problem happen when your Internet connection drops, or when your VPN disconnects for some other reason?

If you can, please post the diagnostic info obtained by following the instructions at Read Before You Post.

Sometimes the problem is not with Tunnelblick or its settings, but caused by the OpenVPN configuration and/or the OpenVPN server or the configuration of the OpenVPN server. You might want to contact whoever provides you with VPN service.

Ali Afshany

unread,
Aug 26, 2021, 3:11:23 PM8/26/21
to tunnelblick-discuss
sorryi will reply with the details next time.
no the VPN provider is ok≤ because on my android it connects so fast. it is my mac that faces problems,.

Tunnelblick developer

unread,
Aug 26, 2021, 3:13:11 PM8/26/21
to tunnelblick-discuss
Your VPN service provider could still be the problem. They use different configurations for. Android, iOS, Windows, macOS, and Linux, and the different configurations can do different things.

Ali Afshany

unread,
Aug 27, 2021, 3:17:50 AM8/27/21
to tunnelblick-discuss
this is a copy of diagnostic, please consider that the "Make sure that "Check if the apparent public IP address changed after connecting" is checked." is greryish and i was unable to check it.

*Tunnelblick: macOS 11.5.1 (20G80); Tunnelblick 3.8.7beta01 (build 5720); prior version 3.8.6 (build 5710); Admin user
git commit 17c04f22383ee76c0bceb096d59595a07111fe76
The Tunnelblick.app process is not being translated (x86_64)
System Integrity Protection is enabled

Configuration de1019.nordvpn.com.udp1194

"Sanitized" condensed configuration file for /Library/Application Support/Tunnelblick/Shared/de1019.nordvpn.com.udp1194.tblk:

client
dev tun
proto udp
remote 5.****175 1194
resolv-retry infinite
remote-random
nobind
tun-mtu 1500
tun-mtu-extra 32
mssfix 1450
persist-key
persist-tun
ping 15
ping-restart 0
ping-timer-rem
reneg-sec 0
comp-lzo no
remote-cert-tls server
auth-user-pass
verb 3
pull
fast-io
cipher AES-256-CBC
auth SHA512
<ca>
[Security-related line(s) omitted]
</ca>
key-direction 1
<tls-auth>
[Security-related line(s) omitted]
</tls-auth>


================================================================================

Files in **.nordvpn.com.udp1194.tblk:
      Contents/Resources/config.ovpn

================================================================================

Tunnelblick Kext Policy Data:

net.tunnelblick.tap|Z2SG5H3HC8|Jonathan Bullard|0|4
net.tunnelblick.tun|Z2SG5H3HC8|Jonathan Bullard|0|4

================================================================================

Configuration preferences:

-skipWarningThatNotUsingSpecifiedOpenVPN = 1
autoConnect = 1
-onSystemStart = 0
-doNotDisconnectOnFastUserSwitch = 1
-doNotReconnectOnFastUserSwitch = 1
-runMtuTest = 1
-keychainHasUsernameAndPassword = 1
-openvpnVersion = 2.4.11-openssl-1.1.1l
-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0
-keepConnected = 1
-doNotDisconnectOnSleep = 1
-loginWindowSecurityTokenCheckboxIsChecked = 0
-lastConnectionSucceeded = 1

================================================================================

Wildcard preferences:

-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0

================================================================================

Program preferences:

allowNonAdminSafeConfigurationReplacement = 1 (forced)
inhibitOutboundTunneblickTraffic = 1
launchAtNextLogin = 1
tunnelblickVersionHistory = (
    "3.8.7beta01 (build 5720)",
    "3.8.6 (build 5710)"
)
statusDisplayNumber = 0
lastLaunchTime = 651735427.331774
lastLanguageAtLaunchWasRTL = 0
connectionWindowDisplayCriteria = showWhenConnecting
maxLogDisplaySize = 102400
lastConnectedDisplayName = de1019.nordvpn.com.udp1194
keyboardShortcutIndex = 1
namedCredentialsThatAllConfigurationsUse = Common
updateCheckAutomatically = 1
updateCheckBetas = 1
NSWindow Frame SettingsSheetWindow = 12 316 829 548 0 0 1440 875
NSWindow Frame ConnectingWindow = 525 493 389 217 0 0 1440 875
NSWindow Frame SUStatusFrame = 757 507 400 135 0 0 1440 875
NSWindow Frame SUUpdateAlert = 723 236 700 628 0 0 1440 875
detailsWindowFrameVersion = 5720
detailsWindowFrame = {{12, 12}, {1416, 852}}
detailsWindowLeftFrame = {{0, 0}, {261, 732}}
detailsWindowViewIndex = 0
detailsWindowConfigurationsTabIdentifier = settings
leftNavSelectedDisplayName = **.nordvpn.com.udp1194
AdvancedWindowTabIdentifier = connectingAndDisconnecting
haveDealtWithOldTunTapPreferences = 1
haveDealtWithAlwaysShowLoginWindow = 1
haveDealtWithOldLoginItem = 1
haveDealtWithAfterDisconnect = 1
SUEnableAutomaticChecks = 0
SUScheduledCheckInterval = 86400
SULastCheckTime = 2021-08-26 19:37:57 +0000
SUHasLaunchedBefore = 1
WebKitDefaultFontSize = 16
WebKitStandardFont = Times

================================================================================

Forced preferences:

{
    allowNonAdminSafeConfigurationReplacement = 1;
}

================================================================================

Deployed forced preferences:

(None)

================================================================================

Tunnelblick Log:

2021-08-27 11:34:40.534023 *Tunnelblick: macOS 11.5.1 (20G80); Tunnelblick 3.8.7beta01 (build 5720); prior version 3.8.6 (build 5710)
2021-08-27 11:34:40.685417 *Tunnelblick: Attempting connection with de1019.nordvpn.com.udp1194; Set nameserver = 769; monitoring connection
2021-08-27 11:34:40.685842 *Tunnelblick: openvpnstart start de1019.nordvpn.com.udp1194.tblk 62609 769 0 3 0 34654512 -ptADGNWradsgnw 2.4.11-openssl-1.1.1l
2021-08-27 11:34:40.723834 *Tunnelblick: openvpnstart starting OpenVPN
2021-08-27 11:34:41.452231 OpenVPN 2.4.11 x86_64-apple-darwin [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [MH/RECVDA] [AEAD] built on Aug 24 2021
2021-08-27 11:34:41.452724 library versions: OpenSSL 1.1.1l  24 Aug 2021, LZO 2.10
2021-08-27 11:34:41.455345 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:62609
2021-08-27 11:34:41.455384 Need hold release from management interface, waiting...
2021-08-27 11:34:41.949561 *Tunnelblick: openvpnstart log:
     OpenVPN started successfully.
     Command used to start OpenVPN (one argument per displayed line):
          /Applications/Tunnelblick.app/Contents/Resources/openvpn/openvpn-2.4.11-openssl-1.1.1l/openvpn
          --daemon
          --log /Library/Application Support/Tunnelblick/Logs/-SLibrary-SApplication Support-STunnelblick-SShared-Sde1019.nordvpn.com.udp1194.tblk-SContents-SResources-Sconfig.ovpn.769_0_3_0_34654512.62609.openvpn.log
          --cd /Library/Application Support/Tunnelblick/Shared/de1019.nordvpn.com.udp1194.tblk/Contents/Resources
          --machine-readable-output
          --setenv IV_GUI_VER "net.tunnelblick.tunnelblick 5720 3.8.7beta01 (build 5720)"
          --verb 3
          --config /Library/Application Support/Tunnelblick/Shared/de1019.nordvpn.com.udp1194.tblk/Contents/Resources/config.ovpn
          --setenv TUNNELBLICK_CONFIG_FOLDER /Library/Application Support/Tunnelblick/Shared/de1019.nordvpn.com.udp1194.tblk/Contents/Resources
          --verb 3
          --cd /Library/Application Support/Tunnelblick/Shared/de1019.nordvpn.com.udp1194.tblk/Contents/Resources
          --management 127.0.0.1 62609 /Library/Application Support/Tunnelblick/igcddeopajllcdiehjepenbhhbcgndmkmjmpmpik.mip
          --mtu-test
          --management-query-passwords
          --management-hold
          --script-security 2
          --route-up /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw
          --down /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw
2021-08-27 11:34:41.953910 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:62609
2021-08-27 11:34:41.968734 *Tunnelblick: Established communication with OpenVPN
2021-08-27 11:34:41.968968 MANAGEMENT: CMD 'pid'
2021-08-27 11:34:41.969131 MANAGEMENT: CMD 'auth-retry interact'
2021-08-27 11:34:41.969495 MANAGEMENT: CMD 'state on'
2021-08-27 11:34:41.969533 *Tunnelblick: >INFO:OpenVPN Management Interface Version 1 -- type 'help' for more info
2021-08-27 11:34:41.969582 MANAGEMENT: CMD 'state'
2021-08-27 11:34:41.969653 MANAGEMENT: CMD 'bytecount 1'
2021-08-27 11:34:41.973306 MANAGEMENT: CMD 'hold release'
2021-08-27 11:34:42.000371 *Tunnelblick: Obtained VPN username and password from the Keychain
2021-08-27 11:34:42.001406 MANAGEMENT: CMD 'username "Auth" "96oTmTTeXaHaX5bs2iCNNvMB"'
2021-08-27 11:34:42.001634 MANAGEMENT: CMD 'password [...]'
2021-08-27 11:34:42.003417 WARNING: --ping should normally be used with --ping-restart or --ping-exit
2021-08-27 11:34:42.004603 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2021-08-27 11:34:42.023766 Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
2021-08-27 11:34:42.023794 Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
2021-08-27 11:34:42.024015 TCP/UDP: Preserving recently used remote address: [AF_INET]5.180.62.175:1194
2021-08-27 11:34:42.024140 Socket Buffers: R=[786896->786896] S=[9216->9216]
2021-08-27 11:34:42.024164 UDP link local: (not bound)
2021-08-27 11:34:42.024182 UDP link remote: [AF_INET]5.180.62.175:1194
2021-08-27 11:34:42.024253 MANAGEMENT: >STATE:1630047882,WAIT,,,,,,
2021-08-27 11:34:42.143301 MANAGEMENT: >STATE:1630047882,AUTH,,,,,,
2021-08-27 11:34:42.143363 TLS: Initial packet from [AF_INET]5.180.62.175:1194, sid=94eb90a8 a9f8875d
2021-08-27 11:34:42.424818 VERIFY OK: depth=2, C=PA, O=NordVPN, CN=NordVPN Root CA
2021-08-27 11:34:42.426316 VERIFY OK: depth=1, C=PA, O=NordVPN, CN=NordVPN CA6
2021-08-27 11:34:42.427053 VERIFY KU OK
2021-08-27 11:34:42.427087 Validating certificate extended key usage
2021-08-27 11:34:42.427108 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
2021-08-27 11:34:42.427134 VERIFY EKU OK
2021-08-27 11:34:42.427150 VERIFY OK: depth=0, CN=de1019.nordvpn.com
2021-08-27 11:34:42.561593 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, 4096 bit RSA
2021-08-27 11:34:42.561703 [de1019.nordvpn.com] Peer Connection Initiated with [AF_INET]5.180.62.175:1194
2021-08-27 11:34:43.664333 MANAGEMENT: >STATE:1630047883,GET_CONFIG,,,,,,
2021-08-27 11:34:43.664997 SENT CONTROL [de1019.nordvpn.com]: 'PUSH_REQUEST' (status=1)
2021-08-27 11:34:43.787566 PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1,dhcp-option DNS 103.86.96.100,dhcp-option DNS 103.86.99.100,sndbuf 524288,rcvbuf 524288,explicit-exit-notify,comp-lzo no,route-gateway 10.8.2.1,topology subnet,ping 60,ping-restart 180,ifconfig 10.8.2.3 255.255.255.0,peer-id 8,cipher AES-256-GCM'
2021-08-27 11:34:43.787755 OPTIONS IMPORT: timers and/or timeouts modified
2021-08-27 11:34:43.787778 OPTIONS IMPORT: explicit notify parm(s) modified
2021-08-27 11:34:43.787790 OPTIONS IMPORT: compression parms modified
2021-08-27 11:34:43.787800 OPTIONS IMPORT: --sndbuf/--rcvbuf options modified
2021-08-27 11:34:43.787823 Socket Buffers: R=[786896->524288] S=[9216->524288]
2021-08-27 11:34:43.787834 OPTIONS IMPORT: --ifconfig/up options modified
2021-08-27 11:34:43.787843 OPTIONS IMPORT: route options modified
2021-08-27 11:34:43.787853 OPTIONS IMPORT: route-related options modified
2021-08-27 11:34:43.787862 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
2021-08-27 11:34:43.787873 OPTIONS IMPORT: peer-id set
2021-08-27 11:34:43.787882 OPTIONS IMPORT: adjusting link_mtu to 1657
2021-08-27 11:34:43.787892 OPTIONS IMPORT: data channel crypto options modified
2021-08-27 11:34:43.787903 Data Channel: using negotiated cipher 'AES-256-GCM'
2021-08-27 11:34:43.788020 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
2021-08-27 11:34:43.788036 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
2021-08-27 11:34:43.788406 Opening utun (connect(AF_SYS_CONTROL)): Resource busy (errno=16)
2021-08-27 11:34:43.788431 Opening utun (connect(AF_SYS_CONTROL)): Resource busy (errno=16)
2021-08-27 11:34:43.788766 Opened utun device utun2
2021-08-27 11:34:43.788904 MANAGEMENT: >STATE:1630047883,ASSIGN_IP,,10.8.2.3,,,,
2021-08-27 11:34:43.788931 /sbin/ifconfig utun2 delete
                           ifconfig: ioctl (SIOCDIFADDR): Can't assign requested address
2021-08-27 11:34:43.830983 NOTE: Tried to delete pre-existing tun/tap instance -- No Problem if failure
2021-08-27 11:34:43.831091 /sbin/ifconfig utun2 10.8.2.3 10.8.2.3 netmask 255.255.255.0 mtu 1500 up
2021-08-27 11:34:43.836191 /sbin/route add -net 10.8.2.0 10.8.2.3 255.255.255.0
                           add net 10.8.2.0: gateway 10.8.2.3
2021-08-27 11:34:43.848830 /sbin/route add -net 5.180.62.175 192.168.1.1 255.255.255.255
                           add net 5.180.62.175: gateway 192.168.1.1
2021-08-27 11:34:43.857609 /sbin/route add -net 0.0.0.0 10.8.2.1 128.0.0.0
                           add net 0.0.0.0: gateway 10.8.2.1
2021-08-27 11:34:43.865563 /sbin/route add -net 128.0.0.0 10.8.2.1 128.0.0.0
                           add net 128.0.0.0: gateway 10.8.2.1
                           11:34:43 *Tunnelblick:  **********************************************
                           11:34:43 *Tunnelblick:  Start of output from client.up.tunnelblick.sh
                           11:34:48 *Tunnelblick:  Disabled IPv6 for 'USB 10/100/1000 LAN'
                           11:34:48 *Tunnelblick:  Disabled IPv6 for 'VM network interface'
                           11:34:48 *Tunnelblick:  Disabled IPv6 for 'Wi-Fi'
                           11:34:48 *Tunnelblick:  Disabled IPv6 for 'Bluetooth PAN'
                           11:34:48 *Tunnelblick:  Disabled IPv6 for 'Thunderbolt Bridge'
                           11:34:48 *Tunnelblick:  Disabled IPv6 for 'Outline'
                           11:34:48 *Tunnelblick:  Disabled IPv6 for 'TorGuard'
                           11:34:48 *Tunnelblick:  Disabled IPv6 for 'StrongVPN WireGuard Configuration'
                           11:34:48 *Tunnelblick:  Disabled IPv6 for 'NordVPN NordLynx'
                           11:34:48 *Tunnelblick:  Disabled IPv6 for 'NordVPN OVPN'
                           11:34:48 *Tunnelblick:  Disabled IPv6 for 'NL'
                           11:34:48 *Tunnelblick:  Retrieved from OpenVPN: name server(s) [ 103.86.96.100 103.86.99.100 ], search domain(s) [ ] and SMB server(s) [ ] and using default domain name [ openvpn ]
                           11:34:48 *Tunnelblick:  WARNING: Ignoring ServerAddresses '103.86.96.100 103.86.99.100' because ServerAddresses was set manually and '-allowChangesToManuallySetNetworkSettings' was not specified
                           11:34:48 *Tunnelblick:  Setting search domains to 'openvpn' because the search domains were not set manually (or are allowed to be changed) and 'Prepend domain name to search domains' was not selected
                           11:34:50 *Tunnelblick:  Saved the DNS and SMB configurations so they can be restored
                           11:34:50 *Tunnelblick:  Did not change DNS ServerAddresses setting of '1.1.1.1 1.0.0.1' (but re-set it)
                           11:34:50 *Tunnelblick:  Changed DNS SearchDomains setting from '' to 'openvpn'
                           11:34:50 *Tunnelblick:  Changed DNS DomainName setting from '' to 'openvpn'
                           11:34:50 *Tunnelblick:  Did not change SMB NetBIOSName setting of ''
                           11:34:50 *Tunnelblick:  Did not change SMB Workgroup setting of ''
                           11:34:50 *Tunnelblick:  Did not change SMB WINSAddresses setting of ''
                           11:34:50 *Tunnelblick:  DNS servers '1.1.1.1 1.0.0.1' were set manually
                           11:34:50 *Tunnelblick:  DNS servers '1.1.1.1 1.0.0.1' will be used for DNS queries when the VPN is active
                           11:34:50 *Tunnelblick:  The DNS servers include only free public DNS servers known to Tunnelblick.
                           11:34:50 *Tunnelblick:  Flushed the DNS cache via dscacheutil
                           11:34:50 *Tunnelblick:  /usr/sbin/discoveryutil not present. Not flushing the DNS cache via discoveryutil
                           11:34:50 *Tunnelblick:  Notified mDNSResponder that the DNS cache was flushed
                           11:34:50 *Tunnelblick:  Not notifying mDNSResponderHelper that the DNS cache was flushed because it is not running
                           11:34:50 *Tunnelblick:  Setting up to monitor system configuration with process-network-changes
                           11:34:50 *Tunnelblick:  End of output from client.up.tunnelblick.sh
                           11:34:50 *Tunnelblick:  **********************************************
2021-08-27 11:34:50.812511 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
2021-08-27 11:34:50.812579 Initialization Sequence Completed
2021-08-27 11:34:50.812647 MANAGEMENT: >STATE:1630047890,CONNECTED,SUCCESS,10.8.2.3,5.180.62.175,1194,,
2021-08-27 11:34:50.812774 NOTE: Beginning empirical MTU test -- results should be available in 3 to 4 minutes.
2021-08-27 11:34:52.047478 *Tunnelblick: DNS address 1.0.0.1 is being routed through the VPN
2021-08-27 11:34:52.157185 *Tunnelblick: DNS address 1.1.1.1 is being routed through the VPN

================================================================================

Down log:

11:34:35 *Tunnelblick:  **********************************************
11:34:35 *Tunnelblick:  Start of output from client.down.tunnelblick.sh
11:34:35 *Tunnelblick:  Cancelled monitoring system configuration changes
11:34:36 *Tunnelblick:  Restored State:DNS
11:34:36 *Tunnelblick:  Restored Setup:DNS
11:34:36 *Tunnelblick:  Removed State:SMB
11:34:36 *Tunnelblick:  Restored DNS and SMB settings
11:34:36 *Tunnelblick:  Re-enabled IPv6 (automatic) for "USB 10/100/1000 LAN"
11:34:36 *Tunnelblick:  Re-enabled IPv6 (automatic) for "VM network interface"
11:34:37 *Tunnelblick:  Re-enabled IPv6 (automatic) for "Wi-Fi"
11:34:37 *Tunnelblick:  Re-enabled IPv6 (automatic) for "Bluetooth PAN"
11:34:37 *Tunnelblick:  Re-enabled IPv6 (automatic) for "Thunderbolt Bridge"
11:34:37 *Tunnelblick:  Re-enabled IPv6 (automatic) for "Outline"
11:34:37 *Tunnelblick:  Re-enabled IPv6 (automatic) for "TorGuard"
11:34:37 *Tunnelblick:  Re-enabled IPv6 (automatic) for "StrongVPN WireGuard Configuration"
11:34:38 *Tunnelblick:  Re-enabled IPv6 (automatic) for "NordVPN NordLynx"
11:34:38 *Tunnelblick:  Re-enabled IPv6 (automatic) for "NordVPN OVPN"
11:34:38 *Tunnelblick:  Re-enabled IPv6 (automatic) for "NL"
11:34:38 *Tunnelblick:  Flushed the DNS cache with dscacheutil -flushcache
11:34:38 *Tunnelblick:  Notified mDNSResponder that the DNS cache was flushed
11:34:38 *Tunnelblick:  End of output from client.down.tunnelblick.sh
11:34:38 *Tunnelblick:  **********************************************

================================================================================

Previous down log:

10:06:23 *Tunnelblick:  **********************************************
10:06:23 *Tunnelblick:  Start of output from client.down.tunnelblick.sh
10:06:23 *Tunnelblick:  Cancelled monitoring system configuration changes
10:06:23 *Tunnelblick:  Restored State:DNS
10:06:23 *Tunnelblick:  Restored Setup:DNS
10:06:23 *Tunnelblick:  Removed State:SMB
10:06:23 *Tunnelblick:  Restored DNS and SMB settings
10:06:23 *Tunnelblick:  Re-enabled IPv6 (automatic) for "USB 10/100/1000 LAN"
10:06:23 *Tunnelblick:  Re-enabled IPv6 (automatic) for "VM network interface"
10:06:23 *Tunnelblick:  Re-enabled IPv6 (automatic) for "Wi-Fi"
10:06:24 *Tunnelblick:  Re-enabled IPv6 (automatic) for "Bluetooth PAN"
10:06:24 *Tunnelblick:  Re-enabled IPv6 (automatic) for "Thunderbolt Bridge"
10:06:24 *Tunnelblick:  Re-enabled IPv6 (automatic) for "Outline"
10:06:24 *Tunnelblick:  Re-enabled IPv6 (automatic) for "TorGuard"
10:06:24 *Tunnelblick:  Re-enabled IPv6 (automatic) for "StrongVPN WireGuard Configuration"
10:06:24 *Tunnelblick:  Re-enabled IPv6 (automatic) for "NordVPN NordLynx"
10:06:24 *Tunnelblick:  Re-enabled IPv6 (automatic) for "NordVPN OVPN"
10:06:24 *Tunnelblick:  Re-enabled IPv6 (automatic) for "NL"
10:06:24 *Tunnelblick:  Flushed the DNS cache with dscacheutil -flushcache
10:06:24 *Tunnelblick:  Notified mDNSResponder that the DNS cache was flushed
10:06:24 *Tunnelblick:  End of output from client.down.tunnelblick.sh
10:06:24 *Tunnelblick:  **********************************************

================================================================================

Network services:

An asterisk (*) denotes that a network service is disabled.
USB 10/100/1000 LAN
VM network interface
Wi-Fi
Bluetooth PAN
Thunderbolt Bridge
Outline
TorGuard
*VPN Unlimited 2
StrongVPN WireGuard Configuration
NordVPN NordLynx
NordVPN OVPN
NL

Wi-Fi Power (en0): On

================================================================================

ifconfig output:

lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
    options=1203<RXCSUM,TXCSUM,TXSTATUS,SW_TIMESTAMP>
    inet 127.0.0.1 netmask 0xff000000
    inet6 ::1 prefixlen 128
    inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1
    nd6 options=201<PERFORMNUD,DAD>
gif0: flags=8010<POINTOPOINT,MULTICAST> mtu 1280
stf0: flags=0<> mtu 1280
en7: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
    ether ac:de:48:00:11:22
    inet6 fe80::aede:48ff:fe00:1122%en7 prefixlen 64 scopeid 0x4
    nd6 options=201<PERFORMNUD,DAD>
    media: autoselect
    status: active
en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
    options=400<CHANNEL_IO>
    ether 78:4f:43:72:a3:0f
    inet 192.168.1.131 netmask 0xffffff00 broadcast 192.168.1.255
    nd6 options=201<PERFORMNUD,DAD>
    media: autoselect
    status: active
en1: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
    options=460<TSO4,TSO6,CHANNEL_IO>
    ether 82:88:a1:26:1c:01
    media: autoselect <full-duplex>
    status: inactive
en2: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
    options=460<TSO4,TSO6,CHANNEL_IO>
    ether 82:88:a1:26:1c:00
    media: autoselect <full-duplex>
    status: inactive
en3: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
    options=460<TSO4,TSO6,CHANNEL_IO>
    ether 82:88:a1:26:1c:05
    media: autoselect <full-duplex>
    status: inactive
en4: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
    options=460<TSO4,TSO6,CHANNEL_IO>
    ether 82:88:a1:26:1c:04
    media: autoselect <full-duplex>
    status: inactive
en5: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
    options=6467<RXCSUM,TXCSUM,VLAN_MTU,TSO4,TSO6,CHANNEL_IO,PARTIAL_CSUM,ZEROINVERT_CSUM>
    ether a0:ce:c8:e2:18:c3
    nd6 options=201<PERFORMNUD,DAD>
    media: autoselect (none)
    status: inactive
bridge0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
    options=63<RXCSUM,TXCSUM,TSO4,TSO6>
    ether 82:88:a1:26:1c:01
    Configuration:
        id 0:0:0:0:0:0 priority 0 hellotime 0 fwddelay 0
        maxage 0 holdcnt 0 proto stp maxaddr 100 timeout 1200
        root id 0:0:0:0:0:0 priority 0 ifcost 0 port 0
        ipfilter disabled flags 0x0
    member: en1 flags=3<LEARNING,DISCOVER>
            ifmaxaddr 0 port 6 priority 0 path cost 0
    member: en2 flags=3<LEARNING,DISCOVER>
            ifmaxaddr 0 port 7 priority 0 path cost 0
    member: en3 flags=3<LEARNING,DISCOVER>
            ifmaxaddr 0 port 8 priority 0 path cost 0
    member: en4 flags=3<LEARNING,DISCOVER>
            ifmaxaddr 0 port 9 priority 0 path cost 0
    nd6 options=201<PERFORMNUD,DAD>
    media: <unknown type>
    status: inactive
p2p0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 2304
    options=400<CHANNEL_IO>
    ether 0a:4f:43:72:a3:0f
    media: autoselect
    status: inactive
awdl0: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1484
    options=400<CHANNEL_IO>
    ether e2:9e:27:79:ab:19
    inet6 fe80::e09e:27ff:fe79:ab19%awdl0 prefixlen 64 scopeid 0xd
    nd6 options=201<PERFORMNUD,DAD>
    media: autoselect
    status: active
llw0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
    options=400<CHANNEL_IO>
    ether e2:9e:27:79:ab:19
    inet6 fe80::e09e:27ff:fe79:ab19%llw0 prefixlen 64 scopeid 0xe
    nd6 options=201<PERFORMNUD,DAD>
    media: autoselect
    status: active
utun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1380
    inet6 fe80::8ac2:7b75:9ab2:f9ef%utun0 prefixlen 64 scopeid 0xf
    nd6 options=201<PERFORMNUD,DAD>
utun1: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 2000
    inet6 fe80::dbfa:da1f:daf6:a21c%utun1 prefixlen 64 scopeid 0x10
    nd6 options=201<PERFORMNUD,DAD>
utun2: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1500
    inet 10.8.2.3 --> 10.8.2.3 netmask 0xffffff00

================================================================================

Non-Apple kexts that are loaded:

Index Refs Address            Size       Wired      Name (Version) UUID <Linked Against>
  180    0 0xffffff7f9cd7a000 0x12000    0x12000    com.tuxera.filesystems.tuxera_ntfs (2021.1.7) 2557AE80-E1B9-3978-A687-DEE1D8126967 <8 6 5 3 1>
  190    0 0xffffff7f9ccb0000 0x7e000    0x7e000    com.highpoint-tech.kext.HighPointRR (4.22.1) 6DF47B93-DB65-36BD-9392-0101CFDDDDFF <189 14 6 5 3>
  191    0 0xffffff7f9cd3b000 0x2f000    0x2f000    com.softraid.driver.SoftRAID (6.0) CBBE85C9-E1A8-3C3B-A4D3-DC690B0898D8 <30 6 5 3>
  192    0 0xffffff7f9cca1000 0xb000     0xb000     com.highpoint-tech.kext.HighPointIOP (4.4.5) 571AEA63-3845-3A83-B37F-5FD117C0FFDE <189 14 6 5 3>

================================================================================

Quit Log:

2021-08-27 10:06:19.191367 applicationShouldTerminate: termination because of logout; delayed until 'shutdownTunnelblick' finishes)
2021-08-27 10:06:19.469528 shutDownTunnelblick: started.
2021-08-27 10:06:19.470109 shutDownTunnelblick: Starting cleanup.
2021-08-27 10:06:19.470644 cleanup: Entering cleanup
2021-08-27 10:06:19.471161 synchronized user defaults
2021-08-27 10:06:26.709941 shutDownTunnelblick: Cleanup finished.
2021-08-27 10:06:26.710374 Finished shutting down Tunnelblick; allowing termination

================================================================================

Console Log:

2021-08-27 10:06:45.534550 com.apple.xpc.launchd[1] Coalition Cache Evicted: app<application.net.tunnelblick.tunnelblick.5622319.5622574(501)> [2756]
2021-08-27 10:06:45.534641 com.apple.xpc.launchd[1] Coalition Cache Hit: app<application.net.tunnelblick.tunnelblick.5726825.5726831(501)> [7545]
2021-08-27 10:29:07.714624 com.apple.xpc.launchd[1] Coalition Cache Evicted: app<application.net.tunnelblick.tunnelblick.5640604.5640610(501)> [4330]
2021-08-27 11:07:42.109083 com.apple.xpc.launchd[1] Coalition Cache Evicted: app<application.net.tunnelblick.tunnelblick.5712696.5712951(501)> [6828]
2021-08-27 11:17:45.295968 com.apple.xpc.launchd[1] Coalition Cache Evicted: app<application.net.tunnelblick.tunnelblick.22.28(501)> [2740]


Tunnelblick developer

unread,
Aug 27, 2021, 7:12:37 AM8/27/21
to tunnelblick-discuss
"Check if the apparent public IP address changed after connecting" is disabled because you have enabled "Inhibit automatic update checking and IP Address checking" on the "Preferences" panel of Tunnelblick's "VPN Details" window.

The "Inhibit…" checkbox is designed to disable all use of the Internet by the Tunnelblick application itself and allow only traffic generated by OpenVPN.

Tunnelblick developer

unread,
Aug 27, 2021, 7:37:25 AM8/27/21
to tunnelblick-discuss
Not causing the problem you originally reported (lose VPN but Tunnelblick doesn't notice), but you have checked "Run MTU maximum size test after connecting" on the "While Connected" tab of Tunnelblick's "Advanced" window. That is not something that should usually be checked because it does testing in the background for several minutes while the VPN is connected.

Finally, about the original problem you reported: The OpenVPN options "ping" and "ping-restart" are used to detect network failures. Your OpenVPN configuration file specifies "ping 15" and "ping-restart 0". The OpenVPN server "pushes" "ping 60" and "ping-restart 180". I don't know which one is being used.
  • If the "ping-restart 0" is being used then that is the cause of the problem because it disables OpenVPN's ability to detect network failures.

  • If the "ping-restart 180" is being used then OpenVPN will not consider the network  to have failed for three minutes (180 seconds). You might to lower that number (and the "ping" number) to detect network failures faster.
Please see the OpenVPN man page or consult OpenVPN experts, listed on our Support page, for more information about OpenVPN configuration issues.

Or consult your VPN service provider.

Ali Afshany

unread,
Aug 27, 2021, 7:53:35 AM8/27/21
to tunnelblick-discuss
Wow, you have really investigated this. i really appreciate your time and energy on this.
The settings you suggested will definitely be considered and if necessary, I will let you know the result later.

I wish you the best
Reply all
Reply to author
Forward
0 new messages