macOS Big Sur VPN connected no internet

253 views
Skip to first unread message

Sayu

unread,
Sep 9, 2021, 12:31:50 AM9/9/21
to tunnelblick-discuss
VPN Connected but no internet. I tried various configuration settings but none of them worked. Any suggestions would be appreciated.


----------------------------------------------------------------------------------

*Tunnelblick: macOS 11.5.2 (20G95); Tunnelblick 3.8.6 (build 5710); Admin user
git commit 7418568496b47385558663b1afcc286232c8062f
The Tunnelblick.app process is not being translated (arm64)
System Integrity Protection is enabled

Configuration PNS

"Sanitized" condensed configuration file for /Users/I852338/Library/Application Support/Tunnelblick/Configurations/PNS.tblk:

client
tls-client
auth SHA256
cipher AES-256-CBC
remote-cert-tls server
tls-version-min 1.2
proto udp
remote 20.151.31.250 1194
dev tun
resolv-retry 5
nobind
keepalive 5 30
compress lzo
persist-key
persist-tun
verb 3
route-method exe
route-delay 2
key-direction 1
<ca>
[Security-related line(s) omitted]
</ca>
<tls-auth>
[Security-related line(s) omitted]
</tls-auth>
<cert>
[Security-related line(s) omitted]
</cert>
<key>
[Security-related line(s) omitted]
</key>
auth-user-pass


================================================================================

Files in PNS.tblk:
      Contents/Resources/config.ovpn

================================================================================

Tunnelblick Kext Policy Data:



================================================================================

Configuration preferences:

useDNS = 1
-notMonitoringConnection = 0
-resetPrimaryInterfaceAfterDisconnect = 1
-resetPrimaryInterfaceAfterUnexpectedDisconnect = 1
-routeAllTrafficThroughVpn = 0
-doNotFlushCache = 0
-useUpInsteadOfRouteUp = 0
-keychainHasUsernameAndPassword = 1
-loadTap = 
-loadTun = 
-openvpnVersion = 
-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0
-keepConnected = 1
-doNotDisableIpv6onTun = 1
-loggingLevel = 3
-allowChangesToManuallySetNetworkSettings = 1
-disableNetworkAccessAfterDisconnect = 0
-disableNetworkAccessAfterUnexpectedDisconnect = 0
-loginWindowSecurityTokenCheckboxIsChecked = 0
-changeDNSServersAction = ignore
-changeOtherDNSServersAction = ignore
-changeOtherDomainAction = 
-changeOtherSearchDomainAction = 
-changeOtherWINSServersAction = 
-changeOtherNetBIOSNameAction = 
-changeOtherWorkgroupAction = 
-lastConnectionSucceeded = 1
-prependDomainNameToSearchDomains = 0

================================================================================

Wildcard preferences:

-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0

================================================================================

Program preferences:

launchAtNextLogin = 1
menuIconSet = 3.3.TBMenuIcons
tunnelblickVersionHistory = (
    "3.8.6 (build 5710)"
)
lastLaunchTime = 652852930.853968
lastLanguageAtLaunchWasRTL = 0
connectionWindowDisplayCriteria = showWhenConnecting
maxLogDisplaySize = 102400
lastConnectedDisplayName = PNS
keyboardShortcutIndex = 1
updateCheckAutomatically = 1
NSWindow Frame SettingsSheetWindow = 400 165 829 548 0 0 1440 875 
NSWindow Frame ConnectingWindow = 525 514 389 217 0 0 1440 875 
detailsWindowFrameVersion = 5710
detailsWindowFrame = {{514, 334}, {760, 476}}
detailsWindowLeftFrame = {{0, 0}, {136.5, 356}}
detailsWindowViewIndex = 0
detailsWindowConfigurationsTabIdentifier = log
leftNavSelectedDisplayName = PNS
AdvancedWindowTabIdentifier = connectingAndDisconnecting
haveDealtWithOldTunTapPreferences = 1
haveDealtWithAlwaysShowLoginWindow = 1
haveDealtWithOldLoginItem = 1
haveDealtWithAfterDisconnect = 1
SUEnableAutomaticChecks = 1
SUScheduledCheckInterval = 86400
SULastCheckTime = 2021-09-09 04:02:11 +0000
SUHasLaunchedBefore = 1
WebKitDefaultFontSize = 16
WebKitStandardFont = Times

================================================================================

Forced preferences:

(None)

================================================================================

Deployed forced preferences:

(None)

================================================================================

Tunnelblick Log:

2021-09-08 23:18:38.911644 *Tunnelblick: macOS 11.5.2 (20G95); Tunnelblick 3.8.6 (build 5710)
2021-09-08 23:18:39.541282 *Tunnelblick: Attempting connection with PNS using shadow copy; Set nameserver = 769; monitoring connection
2021-09-08 23:18:39.542163 *Tunnelblick: openvpnstart start PNS.tblk 50749 769 0 1 0 44155184 -ptDGNWrdsgnw 2.5.3-openssl-1.1.1l
2021-09-08 23:18:39.576649 *Tunnelblick: openvpnstart starting OpenVPN
2021-09-08 23:18:39.959537 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2021-09-08 23:18:39.960238 DEPRECATED OPTION: --cipher set to 'AES-256-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM). Future OpenVPN version will ignore --cipher for cipher negotiations. Add 'AES-256-CBC' to --data-ciphers or change --cipher 'AES-256-CBC' to --data-ciphers-fallback 'AES-256-CBC' to silence this warning.
2021-09-08 23:18:39.960646 OpenVPN 2.5.3 x86_64-apple-darwin [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [MH/RECVDA] [AEAD] built on Aug 24 2021
2021-09-08 23:18:39.960691 library versions: OpenSSL 1.1.1l  24 Aug 2021, LZO 2.10
2021-09-08 23:18:39.962246 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:50749
2021-09-08 23:18:39.962267 Need hold release from management interface, waiting...
2021-09-08 23:18:40.168187 *Tunnelblick: openvpnstart log:
     OpenVPN started successfully.
     Command used to start OpenVPN (one argument per displayed line):
          /Applications/Tunnelblick.app/Contents/Resources/openvpn/openvpn-2.5.3-openssl-1.1.1l/openvpn
          --daemon
          --log /Library/Application Support/Tunnelblick/Logs/-SUsers-SI852338-SLibrary-SApplication Support-STunnelblick-SConfigurations-SPNS.tblk-SContents-SResources-Sconfig.ovpn.769_0_1_0_44155184.50749.openvpn.log
          --cd /Library/Application Support/Tunnelblick/Users/I852338/PNS.tblk/Contents/Resources
          --machine-readable-output
          --setenv IV_GUI_VER "net.tunnelblick.tunnelblick 5710 3.8.6 (build 5710)"
          --verb 3
          --config /Library/Application Support/Tunnelblick/Users/I852338/PNS.tblk/Contents/Resources/config.ovpn
          --setenv TUNNELBLICK_CONFIG_FOLDER /Library/Application Support/Tunnelblick/Users/I852338/PNS.tblk/Contents/Resources
          --verb 3
          --cd /Library/Application Support/Tunnelblick/Users/I852338/PNS.tblk/Contents/Resources
          --management 127.0.0.1 50749 /Library/Application Support/Tunnelblick/kjfompghagdhkbboidchhinjbjbnjhojokndbooa.mip
          --management-query-passwords
          --management-hold
          --script-security 2
          --route-up /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -d -f -m -o -r -ru -w -ptDGNWrdsgnw
          --down /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -d -f -m -o -r -ru -w -ptDGNWrdsgnw
2021-09-08 23:18:40.179965 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:50749
2021-09-08 23:18:40.206750 MANAGEMENT: CMD 'pid'
2021-09-08 23:18:40.206848 MANAGEMENT: CMD 'auth-retry interact'
2021-09-08 23:18:40.206880 MANAGEMENT: CMD 'state on'
2021-09-08 23:18:40.206907 MANAGEMENT: CMD 'state'
2021-09-08 23:18:40.206945 MANAGEMENT: CMD 'bytecount 1'
2021-09-08 23:18:40.209110 *Tunnelblick: Established communication with OpenVPN
2021-09-08 23:18:40.231787 *Tunnelblick: >INFO:OpenVPN Management Interface Version 3 -- type 'help' for more info
2021-09-08 23:18:40.232864 MANAGEMENT: CMD 'hold release'
2021-09-08 23:18:40.243977 *Tunnelblick: Obtained VPN username and password from the Keychain
2021-09-08 23:18:40.245480 MANAGEMENT: CMD 'username "Auth" "I852338"'
2021-09-08 23:18:40.245560 MANAGEMENT: CMD 'password [...]'
2021-09-08 23:18:40.246213 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2021-09-08 23:18:40.248609 Outgoing Control Channel Authentication: Using 256 bit message hash 'SHA256' for HMAC authentication
2021-09-08 23:18:40.248641 Incoming Control Channel Authentication: Using 256 bit message hash 'SHA256' for HMAC authentication
2021-09-08 23:18:40.249041 TCP/UDP: Preserving recently used remote address: [AF_INET]20.151.31.250:1194
2021-09-08 23:18:40.249125 Socket Buffers: R=[786896->786896] S=[9216->9216]
2021-09-08 23:18:40.249141 UDP link local: (not bound)
2021-09-08 23:18:40.249155 UDP link remote: [AF_INET]20.151.31.250:1194
2021-09-08 23:18:40.249176 MANAGEMENT: >STATE:1631161120,WAIT,,,,,,
2021-09-08 23:18:40.327378 MANAGEMENT: >STATE:1631161120,AUTH,,,,,,
2021-09-08 23:18:40.327597 TLS: Initial packet from [AF_INET]20.151.31.250:1194, sid=78828104 90509438
2021-09-08 23:18:40.399122 VERIFY OK: depth=1, CN=OpenVPN-CA-127.0.0.1
2021-09-08 23:18:40.399625 VERIFY KU OK
2021-09-08 23:18:40.399642 Validating certificate extended key usage
2021-09-08 23:18:40.399655 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
2021-09-08 23:18:40.399666 VERIFY EKU OK
2021-09-08 23:18:40.399677 VERIFY OK: depth=0, CN=OpenVPN-Server-127.0.0.1
2021-09-08 23:18:40.581647 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 2048 bit RSA, signature: RSA-SHA256
2021-09-08 23:18:40.581804 [OpenVPN-Server-127.0.0.1] Peer Connection Initiated with [AF_INET]20.151.31.250:1194
2021-09-08 23:18:41.665572 MANAGEMENT: >STATE:1631161121,GET_CONFIG,,,,,,
2021-09-08 23:18:41.665798 SENT CONTROL [OpenVPN-Server-127.0.0.1]: 'PUSH_REQUEST' (status=1)
2021-09-08 23:18:41.755803 PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1 bypass-dhcp,route 10.232.64.64  255.255.255.192,route 10.232.66.0  255.255.255.0,route 10.232.65.0  255.255.255.128,dhcp-option DNS 1.0.0.1,dhcp-option DNS 1.1.1.1,dhcp-option DNS 8.8.8.8,dhcp-option DNS 8.8.4.4,route 10.9.0.1,topology net30,ping 5,ping-restart 30,ifconfig 10.9.0.6 10.9.0.5,peer-id 0,cipher AES-256-GCM'
2021-09-08 23:18:41.756121 OPTIONS IMPORT: timers and/or timeouts modified
2021-09-08 23:18:41.756145 OPTIONS IMPORT: --ifconfig/up options modified
2021-09-08 23:18:41.756162 OPTIONS IMPORT: route options modified
2021-09-08 23:18:41.756178 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
2021-09-08 23:18:41.756193 OPTIONS IMPORT: peer-id set
2021-09-08 23:18:41.756208 OPTIONS IMPORT: adjusting link_mtu to 1625
2021-09-08 23:18:41.756223 OPTIONS IMPORT: data channel crypto options modified
2021-09-08 23:18:41.756271 Data Channel: using negotiated cipher 'AES-256-GCM'
2021-09-08 23:18:41.756433 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
2021-09-08 23:18:41.756452 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
2021-09-08 23:18:41.758883 Opened utun device utun6
2021-09-08 23:18:41.759289 MANAGEMENT: >STATE:1631161121,ASSIGN_IP,,10.9.0.6,,,,
2021-09-08 23:18:41.759727 /sbin/ifconfig utun6 delete
                           ifconfig: ioctl (SIOCDIFADDR): Can't assign requested address
2021-09-08 23:18:41.775927 NOTE: Tried to delete pre-existing tun/tap instance -- No Problem if failure
2021-09-08 23:18:41.776055 /sbin/ifconfig utun6 10.9.0.6 10.9.0.5 mtu 1500 netmask 255.255.255.255 up
2021-09-08 23:18:43.866141 /sbin/route add -net 20.151.31.250 192.168.1.254 255.255.255.255
                           add net 20.151.31.250: gateway 192.168.1.254
2021-09-08 23:18:43.880390 /sbin/route add -net 0.0.0.0 10.9.0.5 128.0.0.0
                           add net 0.0.0.0: gateway 10.9.0.5
2021-09-08 23:18:43.884632 /sbin/route add -net 128.0.0.0 10.9.0.5 128.0.0.0
                           add net 128.0.0.0: gateway 10.9.0.5
2021-09-08 23:18:43.888919 MANAGEMENT: >STATE:1631161123,ADD_ROUTES,,,,,,
2021-09-08 23:18:43.888975 /sbin/route add -net 10.232.64.64 10.9.0.5 255.255.255.192
                           add net 10.232.64.64: gateway 10.9.0.5
2021-09-08 23:18:43.893894 /sbin/route add -net 10.232.66.0 10.9.0.5 255.255.255.0
                           add net 10.232.66.0: gateway 10.9.0.5
2021-09-08 23:18:43.898308 /sbin/route add -net 10.232.65.0 10.9.0.5 255.255.255.128
                           add net 10.232.65.0: gateway 10.9.0.5
2021-09-08 23:18:43.903399 /sbin/route add -net 10.9.0.1 10.9.0.5 255.255.255.255
                           add net 10.9.0.1: gateway 10.9.0.5
                           23:18:43 *Tunnelblick:  **********************************************
                           23:18:43 *Tunnelblick:  Start of output from client.up.tunnelblick.sh
                           23:18:46 *Tunnelblick:  Retrieved from OpenVPN: name server(s) [ 1.0.0.1 1.1.1.1 8.8.8.8 8.8.4.4 ], search domain(s) [ ] and SMB server(s) [ ] and using default domain name [ openvpn ]
                           23:18:46 *Tunnelblick:  Not aggregating ServerAddresses because running on macOS 10.6 or higher
                           23:18:46 *Tunnelblick:  Setting search domains to 'openvpn' because the search domains were not set manually (or are allowed to be changed) and 'Prepend domain name to search domains' was not selected
                           23:18:48 *Tunnelblick:  Saved the DNS and SMB configurations so they can be restored
                           23:18:48 *Tunnelblick:  Changed DNS ServerAddresses setting from '127.0.0.1' to '1.0.0.1 1.1.1.1 8.8.8.8 8.8.4.4'
                           23:18:48 *Tunnelblick:  Changed DNS SearchDomains setting from 'attlocal.net' to 'openvpn'
                           23:18:48 *Tunnelblick:  Changed DNS DomainName setting from '' to 'openvpn'
                           23:18:48 *Tunnelblick:  Did not change SMB NetBIOSName setting of ''
                           23:18:48 *Tunnelblick:  Did not change SMB Workgroup setting of ''
                           23:18:48 *Tunnelblick:  Did not change SMB WINSAddresses setting of ''
                           23:18:48 *Tunnelblick:  DNS servers '1.0.0.1 1.1.1.1 8.8.8.8 8.8.4.4' will be used for DNS queries when the VPN is active
                           23:18:48 *Tunnelblick:  The DNS servers include only free public DNS servers known to Tunnelblick.
                           23:18:48 *Tunnelblick:  Flushed the DNS cache via dscacheutil
                           23:18:48 *Tunnelblick:  /usr/sbin/discoveryutil not present. Not flushing the DNS cache via discoveryutil
                           23:18:48 *Tunnelblick:  Notified mDNSResponder that the DNS cache was flushed
                           23:18:48 *Tunnelblick:  Notified mDNSResponderHelper that the DNS cache was flushed
                           23:18:48 *Tunnelblick:  Setting up to monitor system configuration with process-network-changes
                           23:18:48 *Tunnelblick:  End of output from client.up.tunnelblick.sh
                           23:18:48 *Tunnelblick:  **********************************************
2021-09-08 23:18:48.224643 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
2021-09-08 23:18:48.224658 Initialization Sequence Completed
2021-09-08 23:18:48.224695 MANAGEMENT: >STATE:1631161128,CONNECTED,SUCCESS,10.9.0.6,20.151.31.250,1194,,
2021-09-08 23:18:49.465129 *Tunnelblick: DNS address 1.0.0.1 is being routed through the VPN
2021-09-08 23:18:49.579203 *Tunnelblick: DNS address 1.1.1.1 is being routed through the VPN
2021-09-08 23:18:49.693197 *Tunnelblick: DNS address 8.8.4.4 is being routed through the VPN
2021-09-08 23:18:49.807908 *Tunnelblick: DNS address 8.8.8.8 is being routed through the VPN
2021-09-08 23:19:32.280745 *Tunnelblick: After 30.0 seconds, gave up trying to fetch IP address information using the ipInfo host's name after connecting.
2021-09-08 23:19:32.732180 *Tunnelblick: fetched IP address information using the ipInfo host's IP address after connecting.

================================================================================

Down log:

23:04:32 *Tunnelblick:  **********************************************
23:04:32 *Tunnelblick:  Start of output from client.down.tunnelblick.sh
23:04:32 *Tunnelblick:  Cancelled monitoring system configuration changes
23:04:32 *Tunnelblick:  Restored State:DNS
23:04:32 *Tunnelblick:  Removed Setup:DNS
23:04:32 *Tunnelblick:  Removed State:SMB
23:04:32 *Tunnelblick:  Restored DNS and SMB settings
23:04:32 *Tunnelblick:  Flushed the DNS cache with dscacheutil -flushcache
23:04:32 *Tunnelblick:  Notified mDNSResponder that the DNS cache was flushed
23:04:32 *Tunnelblick:  Turned off primary interface with networksetup -setairportpower "en0" off
23:04:35 *Tunnelblick:  Turned on primary interface with networksetup -setairportpower "en0" on
23:04:35 *Tunnelblick:  End of output from client.down.tunnelblick.sh
23:04:35 *Tunnelblick:  **********************************************

================================================================================

Previous down log:

22:58:14 *Tunnelblick:  **********************************************
22:58:14 *Tunnelblick:  Start of output from client.down.tunnelblick.sh
22:58:14 *Tunnelblick:  Cancelled monitoring system configuration changes
22:58:14 *Tunnelblick:  Restored State:DNS
22:58:14 *Tunnelblick:  Removed Setup:DNS
22:58:15 *Tunnelblick:  Removed State:SMB
22:58:15 *Tunnelblick:  Restored DNS and SMB settings
22:58:15 *Tunnelblick:  Flushed the DNS cache with dscacheutil -flushcache
22:58:15 *Tunnelblick:  Notified mDNSResponder that the DNS cache was flushed
22:58:15 *Tunnelblick:  Turned off primary interface with networksetup -setairportpower "en0" off
22:58:17 *Tunnelblick:  Turned on primary interface with networksetup -setairportpower "en0" on
22:58:17 *Tunnelblick:  End of output from client.down.tunnelblick.sh
22:58:17 *Tunnelblick:  **********************************************

================================================================================

Network services:

An asterisk (*) denotes that a network service is disabled.
Wi-Fi
Bluetooth PAN
Thunderbolt Bridge


Wi-Fi Power (en0): On

================================================================================

ifconfig output:

lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
options=1203<RXCSUM,TXCSUM,TXSTATUS,SW_TIMESTAMP>
inet 127.0.0.1 netmask 0xff000000 
inet6 ::1 prefixlen 128 
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1 
nd6 options=201<PERFORMNUD,DAD>
gif0: flags=8010<POINTOPOINT,MULTICAST> mtu 1280
stf0: flags=0<> mtu 1280
anpi1: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether 1e:00:07:11:a3:61 
inet6 fe80::1c00:7ff:fe11:a361%anpi1 prefixlen 64 scopeid 0x4 
nd6 options=201<PERFORMNUD,DAD>
media: none
status: inactive
anpi0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether 1e:00:07:11:a3:60 
inet6 fe80::1c00:7ff:fe11:a360%anpi0 prefixlen 64 scopeid 0x5 
nd6 options=201<PERFORMNUD,DAD>
media: none
status: inactive
en3: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether 1e:00:07:11:a3:40 
nd6 options=201<PERFORMNUD,DAD>
media: none
status: inactive
en4: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether 1e:00:07:11:a3:41 
nd6 options=201<PERFORMNUD,DAD>
media: none
status: inactive
en1: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=460<TSO4,TSO6,CHANNEL_IO>
ether 36:6b:8a:23:93:c0 
media: autoselect <full-duplex>
status: inactive
en2: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=460<TSO4,TSO6,CHANNEL_IO>
ether 36:6b:8a:23:93:c4 
media: autoselect <full-duplex>
status: inactive
bridge0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=63<RXCSUM,TXCSUM,TSO4,TSO6>
ether 36:6b:8a:23:93:c0 
Configuration:
id 0:0:0:0:0:0 priority 0 hellotime 0 fwddelay 0
maxage 0 holdcnt 0 proto stp maxaddr 100 timeout 1200
root id 0:0:0:0:0:0 priority 0 ifcost 0 port 0
ipfilter disabled flags 0x0
member: en1 flags=3<LEARNING,DISCOVER>
       ifmaxaddr 0 port 8 priority 0 path cost 0
member: en2 flags=3<LEARNING,DISCOVER>
       ifmaxaddr 0 port 9 priority 0 path cost 0
nd6 options=201<PERFORMNUD,DAD>
media: <unknown type>
status: inactive
ap1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether 3e:06:30:20:ac:ff 
nd6 options=201<PERFORMNUD,DAD>
media: autoselect
status: inactive
en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether 3c:06:30:20:ac:ff 
inet 192.168.1.232 netmask 0xffffff00 broadcast 192.168.1.255
nd6 options=201<PERFORMNUD,DAD>
media: autoselect
status: active
awdl0: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether 2e:ec:e4:9c:52:42 
inet6 fe80::2cec:e4ff:fe9c:5242%awdl0 prefixlen 64 scopeid 0xd 
nd6 options=201<PERFORMNUD,DAD>
media: autoselect
status: active
llw0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether 2e:ec:e4:9c:52:42 
inet6 fe80::2cec:e4ff:fe9c:5242%llw0 prefixlen 64 scopeid 0xe 
nd6 options=201<PERFORMNUD,DAD>
media: autoselect
status: active
utun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1380
inet6 fe80::9f95:617e:c103:9c0c%utun0 prefixlen 64 scopeid 0xf 
nd6 options=201<PERFORMNUD,DAD>
utun1: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 2000
inet6 fe80::979a:951:1b4e:a5a0%utun1 prefixlen 64 scopeid 0x10 
nd6 options=201<PERFORMNUD,DAD>
utun2: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1380
inet6 fe80::3cd8:bdb5:28e5:f877%utun2 prefixlen 64 scopeid 0x11 
nd6 options=201<PERFORMNUD,DAD>
utun3: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1380
inet6 fe80::cb4a:1077:5aa0:6eb1%utun3 prefixlen 64 scopeid 0x12 
nd6 options=201<PERFORMNUD,DAD>
utun4: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1380
inet6 fe80::a200:5e34:c230:9c3f%utun4 prefixlen 64 scopeid 0x13 
nd6 options=201<PERFORMNUD,DAD>
utun5: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1380
inet6 fe80::116d:6762:72f7:3a3f%utun5 prefixlen 64 scopeid 0x14 
nd6 options=201<PERFORMNUD,DAD>
utun6: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1500
inet 10.9.0.6 --> 10.9.0.5 netmask 0xffffffff 

================================================================================

Non-Apple kexts that are loaded:

Index Refs Address            Size       Wired      Name (Version) UUID <Linked Against>

================================================================================

Quit Log:

2021-09-08 22:58:14.516068 applicationShouldTerminate: termination because of Quit; delayed until 'shutdownTunnelblick' finishes)
2021-09-08 22:58:14.519583 shutDownTunnelblick: started.
2021-09-08 22:58:14.521344 shutDownTunnelblick: Starting cleanup.
2021-09-08 22:58:14.521944 cleanup: Entering cleanup
2021-09-08 22:58:14.527485 synchronized user defaults
2021-09-08 22:58:18.703155 shutDownTunnelblick: Cleanup finished.
2021-09-08 22:58:18.704643 Finished shutting down Tunnelblick; allowing termination

================================================================================

Console Log:

2021-09-08 19:26:42.388554 com.apple.xpc.launchd[1] Coalition Cache Hit: app<application.net.tunnelblick.tunnelblick.1878044.1878303(501)> [1941]
2021-09-08 22:09:00.565982 com.apple.xpc.launchd[1] Coalition Cache Hit: app<application.net.tunnelblick.tunnelblick.1878044.1878303(501)> [1941]
2021-09-08 22:11:56.343528 com.apple.xpc.launchd[1] Coalition Cache Hit: app<application.net.tunnelblick.tunnelblick.1878044.1878303(501)> [1941]
2021-09-08 22:25:14.964725 com.apple.xpc.launchd[1] Coalition Cache Hit: app<application.net.tunnelblick.tunnelblick.1878044.1878303(501)> [1941]
2021-09-08 22:36:15.604701 com.apple.xpc.launchd[1] Coalition Cache Hit: app<application.net.tunnelblick.tunnelblick.1878044.1878303(501)> [1941]
2021-09-08 22:46:01.718194 com.apple.xpc.launchd[1] Coalition Cache Hit: app<application.net.tunnelblick.tunnelblick.1878044.1878303(501)> [1941]
2021-09-08 23:02:08.879370 com.apple.xpc.launchd[1] Coalition Cache Hit: app<application.net.tunnelblick.tunnelblick.1878044.1878303(501)> [1941]


Tunnelblick developer

unread,
Sep 9, 2021, 1:17:36 AM9/9/21
to tunnelblick-discuss
1. Nothing to do with this problem, but you should update to the latest stable version of Tunnelblick, 3.8.6a.

2. Probably nothing to do with this problem, but this configuration file and the settings "pushed" by the OpenVPN server to your computer are for Windows. There are some such settings that work only on Windows.

3. These entries:

2021-09-08 23:19:32.280745 *Tunnelblick: After 30.0 seconds, gave up trying to fetch IP address information using the ipInfo host's name after connecting.
2021-09-08 23:19:32.732180 *Tunnelblick: fetched IP address information using the ipInfo host's IP address after connecting.

mean that routing is set up properly, but DNS is not working. The DNS servers ( 1.0.0.1,   1.1.1.1,    8.8.8.8,    and 8.8.4.4 ) were set by the OpenVPN server's "push" directive. The only thing I can think of is that the VPN is not properly forwarding your DNS requests to 1.0.0.1. I don't understand why that would be, since the VPN server is telling to use that, but it could be another difference between Windows and Macs.
  • Until recently, Windows sent all DNS requests to all of the DNS servers and used the first response that came back. So if 1.0.0.1 wasn't working, it wouldn't matter because one of the other DNS servers would probably work.
  • macOS sends only to the first DNS server. If that server doesn't respond within a time out period (I think it's 30 seconds or more), then it tries the next DNS server, and so on. That might be too slow for your Mac to deal with properly.
I think what you should do is try setting DNS to 8.8.8.8 manually (in System Preferences >> Network >> Advanced >> DNS and making sure that "Allow changes to manually-set network settings" is not checked on the "Connecting & Disconnecting" tab of the "Advanced" Tunnelblick settings. (Make sure the configuration you want to change is selected in the "Configurations" panel of Tunnelblick's "VPN Details" window first.)

If that doesn't work, try 8.8.4.4 and 1.1.1.1.

Sayu

unread,
Sep 9, 2021, 6:18:32 PM9/9/21
to tunnelblick-discuss
Thanks, I installed new version of TunnelBlick. Now its working but strangely it shows error first then after couple of minutes sets the correct DNS and internet and VPN both work. Not sure what does highlighted part means but looks like its doing the trick for now.

2021-09-09 16:58:45.314264 *Tunnelblick: Warning: DNS server address 127.0.0.1 is not a public IP address and is not being routed through the VPN.

2021-09-09 16:59:27.533789 *Tunnelblick: After 30.0 seconds, gave up trying to fetch IP address information using the ipInfo host's name after connecting.

2021-09-09 16:59:28.380867 *Tunnelblick: fetched IP address information using the ipInfo host's IP address after connecting.

2021-09-09 17:00:54.468963 *Tunnelblick: process-network-changes: ServerAddresses changed from


Tunnelblick developer

unread,
Sep 9, 2021, 7:07:42 PM9/9/21
to tunnelblick-discuss
Here's what Tunnelblick does to try to diagnose problems::

Tunnelblick first tries to contact tunnelblick.net by using DNS to look up the name.
If that works, then both DNS and routing are working and all is well.
If that fails, Tunnelblick then tries to contact tunnelblick.net by using its IP address, without doing a DNS lookup of "tunnelblick.net".
  • If that works, it means that DNS is not working, but routing is. That's what is shown in the line you highlighted.
  • If that fails, then neither DNS nor routing are working.
The next line:
2021-09-09 17:00:54.468963 *Tunnelblick: process-network-changes: ServerAddresses changed from
shows that something changed the DNS network setting. That started DNS working again.

So there is something wrong with the VPN; it's just that it recovers after a while. (This could be evidence that the first DNS server isn't working, and macOS is switching to another. Unfortunately, you cut off the rest of the log, so I don't know which one didn't work and which one did.

Reply all
Reply to author
Forward
0 new messages