Hi Y'all,
I've got this odd problem I'm trying to sort out. I used to have
tunnelblick 3.1.2 on OS 10.4, worked great. I then migrated to 10.6,
and now I'm seeing this odd problem where the connection establishes
OK, then I lose connectivity, then I see tunnelblick reconnect. The
connection restores for about one minute, then goes dead again, then
tunnelblick reconnects again. Ad nauseum. Here's the config:
client
dev tun
proto udp
cipher AES-256-CBC
remote 11.22.33.44 4444
resolv-retry infinite
nobind
persist-key
persist-tun
mute-replay-warnings
ca /Users/bob/XYZ-CA.crt
cert /Users/bob/bob.crt
key /Users/bob/bob.key
tls-auth /Users/bob/static.key 1
comp-lzo
verb 3
mute 20
auth-user-pass
tls-remote
fw.my.com
And what happens in the log repeatedly (notice at 2011-01-11 21:33:09
it restarts, that happens every minute or two):
2011-01-11 21:31:24 [
fw.my.com] Inactivity timeout (--ping-restart),
restarting
2011-01-11 21:31:24 TCP/UDP: Closing socket
2011-01-11 21:31:24 /Applications/Tunnelblick.app/Contents/Resources/
client.down.tunnelblick.sh -m -w -d tun0 1500 1558 172.30.0.30
172.30.0.29 restart
2011-01-11 21:31:24 *Tunnelblick
client.down.tunnelblick.sh: Cancelled
monitoring of system configuration changes
2011-01-11 21:31:25 SIGUSR1[soft,ping-restart] received, process
restarting
2011-01-11 21:31:25 MANAGEMENT: >STATE:1294810285,RECONNECTING,ping-
restart,,
2011-01-11 21:31:25 MANAGEMENT: CMD 'hold release'
2011-01-11 21:31:25 WARNING: Make sure you understand the semantics of
--tls-remote before using it (see the man page).
2011-01-11 21:31:25 NOTE: the current --script-security setting may
allow this configuration to call user-defined scripts
2011-01-11 21:31:25 Re-using SSL/TLS context
2011-01-11 21:31:25 LZO compression initialized
2011-01-11 21:31:25 Control Channel MTU parms [ L:1558 D:166 EF:66 EB:
0 ET:0 EL:0 ]
2011-01-11 21:31:25 Socket Buffers: R=[42080->65536] S=[9216->65536]
2011-01-11 21:31:25 Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:
135 ET:0 EL:0 AF:3/1 ]
2011-01-11 21:31:25 Local Options hash (VER=V4): '9e7066d2'
2011-01-11 21:31:25 Expected Remote Options hash (VER=V4): '162b04de'
2011-01-11 21:31:25 UDPv4 link local: [undef]
2011-01-11 21:31:25 UDPv4 link remote:
11.22.33.44:4444
2011-01-11 21:31:25 MANAGEMENT: >STATE:1294810285,WAIT,,,
2011-01-11 21:31:25 MANAGEMENT: >STATE:1294810285,AUTH,,,
2011-01-11 21:31:25 TLS: Initial packet from
11.22.33.44:4444,
sid=63e0aae3 31822368
2011-01-11 21:31:25 WARNING: this configuration may cache passwords in
memory -- use the auth-nocache option to prevent this
2011-01-11 21:31:25 VERIFY OK: depth=1, /C=US/ST=California/L=SomeTown/
O=MyGroup/emailAddress=
sup...@my.com/CN=XYZ-CA
2011-01-11 21:31:25 VERIFY X509NAME OK: /C=US/ST=California/O=MyGroup/
CN=
fw.my.com
2011-01-11 21:31:25 VERIFY OK: depth=0, /C=US/ST=California/O=MyGroup/
CN=
fw.my.com
2011-01-11 21:31:25 Data Channel Encrypt: Cipher 'AES-256-CBC'
initialized with 256 bit key
2011-01-11 21:31:25 Data Channel Encrypt: Using 160 bit message hash
'SHA1' for HMAC authentication
2011-01-11 21:31:25 Data Channel Decrypt: Cipher 'AES-256-CBC'
initialized with 256 bit key
2011-01-11 21:31:25 Data Channel Decrypt: Using 160 bit message hash
'SHA1' for HMAC authentication
2011-01-11 21:31:25 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-
AES256-SHA, 1024 bit RSA
2011-01-11 21:31:25 [
fw.my.com] Peer Connection Initiated with
11.22.33.44:4444
2011-01-11 21:31:25 *Tunnelblick
client.down.tunnelblick.sh: Restored
the DNS and WINS configurations
2011-01-11 21:31:26 MANAGEMENT: >STATE:1294810286,GET_CONFIG,,,
2011-01-11 21:31:27 SENT CONTROL [
fw.my.com]:
'PUSH_REQUEST' (status=1)
2011-01-11 21:31:27 PUSH: Received control message: 'PUSH_REPLY,route
172.16.0.0 255.255.0.0,dhcp-option DOMAIN
kilokluster.ucsc.edu,dhcp-
option DNS 128.114.48.44,redirect-gateway def1,route
172.30.0.1,topology net30,ping 10,ping-restart 60,ifconfig 172.30.0.30
172.30.0.29'
2011-01-11 21:31:27 OPTIONS IMPORT: timers and/or timeouts modified
2011-01-11 21:31:27 OPTIONS IMPORT: --ifconfig/up options modified
2011-01-11 21:31:27 OPTIONS IMPORT: route options modified
2011-01-11 21:31:27 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option
options modified
2011-01-11 21:31:27 Preserving previous TUN/TAP instance: tun0
2011-01-11 21:31:27 /Applications/Tunnelblick.app/Contents/Resources/
client.up.tunnelblick.sh -m -w -d tun0 1500 1558 172.30.0.30
172.30.0.29 restart
No such key
2011-01-11 21:31:27 Initialization Sequence Completed
2011-01-11 21:31:27 MANAGEMENT: >STATE:1294810287,CONNECTED,SUCCESS,
172.30.0.30,11.22.33.44
2011-01-11 21:31:27 *Tunnelblick
client.up.tunnelblick.sh: Up to two
'No such key' warnings are normal and may be ignored
2011-01-11 21:31:27 *Tunnelblick
client.up.tunnelblick.sh: Saved the
DNS and WINS configurations for later use
2011-01-11 21:31:27 *Tunnelblick
client.up.tunnelblick.sh: Set up to
monitor system configuration with leasewatch
2011-01-11 21:31:27 *Tunnelblick: Flushed the DNS cache
2011-01-11 21:31:32 *Tunnelblick leasewatch: A system configuration
change was ignored because it was not relevant
2011-01-11 21:33:09 [
fw.my.com] Inactivity timeout (--ping-restart),
restarting
2011-01-11 21:33:09 TCP/UDP: Closing socket
2011-01-11 21:33:09 /Applications/Tunnelblick.app/Contents/Resources/
client.down.tunnelblick.sh -m -w -d tun0 1500 1558 172.30.0.30
172.30.0.29 restart
2011-01-11 21:33:09 SIGUSR1[soft,ping-restart] received, process
restarting
2011-01-11 21:33:09 MANAGEMENT: >STATE:1294810389,RECONNECTING,ping-
restart,,
2011-01-11 21:33:09 MANAGEMENT: CMD 'hold release'
2011-01-11 21:33:09 WARNING: Make sure you understand the semantics of
--tls-remote before using it (see the man page).
2011-01-11 21:33:09 NOTE: the current --script-security setting may
allow this configuration to call user-defined scripts
2011-01-11 21:33:09 Re-using SSL/TLS context
2011-01-11 21:33:09 LZO compression initialized
2011-01-11 21:33:09 Control Channel MTU parms [ L:1558 D:166 EF:66 EB:
0 ET:0 EL:0 ]
2011-01-11 21:33:09 Socket Buffers: R=[42080->65536] S=[9216->65536]
2011-01-11 21:33:09 Data Channel MTU parms [ L:1558 D:1450 EF:58 EB:
135 ET:0 EL:0 AF:3/1 ]
2011-01-11 21:33:09 Local Options hash (VER=V4): '9e7066d2'
2011-01-11 21:33:09 Expected Remote Options hash (VER=V4): '162b04de'
2011-01-11 21:33:09 UDPv4 link local: [undef]
2011-01-11 21:33:09 UDPv4 link remote:
11.22.33.44:4444
2011-01-11 21:33:09 MANAGEMENT: >STATE:1294810389,WAIT,,,
2011-01-11 21:33:09 MANAGEMENT: >STATE:1294810389,AUTH,,,
2011-01-11 21:33:09 TLS: Initial packet from
11.22.33.44:4444,
sid=dc3ff38e 07fb3f11
2011-01-11 21:33:09 WARNING: this configuration may cache passwords in
memory -- use the auth-nocache option to prevent this
2011-01-11 21:33:09 VERIFY OK: depth=1, /C=US/ST=California/L=SomeTown/
O=MyGroup/emailAddress=
sup...@my.com/CN=XYZ-CA
2011-01-11 21:33:09 VERIFY X509NAME OK: /C=US/ST=California/O=MyGroup/
CN=
fw.my.com
2011-01-11 21:33:09 VERIFY OK: depth=0, /C=US/ST=California/O=MyGroup/
CN=
fw.my.com
2011-01-11 21:33:09 Data Channel Encrypt: Cipher 'AES-256-CBC'
initialized with 256 bit key
2011-01-11 21:33:09 Data Channel Encrypt: Using 160 bit message hash
'SHA1' for HMAC authentication
2011-01-11 21:33:09 Data Channel Decrypt: Cipher 'AES-256-CBC'
initialized with 256 bit key
2011-01-11 21:33:09 Data Channel Decrypt: Using 160 bit message hash
'SHA1' for HMAC authentication
2011-01-11 21:33:09 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-
AES256-SHA, 1024 bit RSA
2011-01-11 21:33:09 [
fw.my.com] Peer Connection Initiated with
11.22.33.44:4444
2011-01-11 21:33:09 *Tunnelblick
client.down.tunnelblick.sh: Cancelled
monitoring of system configuration changes
2011-01-11 21:33:09 *Tunnelblick
client.down.tunnelblick.sh: Restored
the DNS and WINS configurations
2011-01-11 21:33:10 MANAGEMENT: >STATE:1294810390,GET_CONFIG,,,
2011-01-11 21:33:11 SENT CONTROL [
fw.my.com]:
'PUSH_REQUEST' (status=1)
2011-01-11 21:33:11 PUSH: Received control message: 'PUSH_REPLY,route
172.16.0.0 255.255.0.0,dhcp-option DOMAIN
kilokluster.ucsc.edu,dhcp-
option DNS 128.114.48.44,redirect-gateway def1,route
172.30.0.1,topology net30,ping 10,ping-restart 60,ifconfig 172.30.0.30
172.30.0.29'
2011-01-11 21:33:11 OPTIONS IMPORT: timers and/or timeouts modified
2011-01-11 21:33:11 OPTIONS IMPORT: --ifconfig/up options modified
2011-01-11 21:33:11 OPTIONS IMPORT: route options modified
2011-01-11 21:33:11 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option
options modified
2011-01-11 21:33:11 Preserving previous TUN/TAP instance: tun0
2011-01-11 21:33:11 /Applications/Tunnelblick.app/Contents/Resources/
client.up.tunnelblick.sh -m -w -d tun0 1500 1558 172.30.0.30
172.30.0.29 restart
No such key
2011-01-11 21:33:11 Initialization Sequence Completed
2011-01-11 21:33:11 MANAGEMENT: >STATE:1294810391,CONNECTED,SUCCESS,
172.30.0.30,11.22.33.44
2011-01-11 21:33:11 *Tunnelblick
client.up.tunnelblick.sh: Up to two
'No such key' warnings are normal and may be ignored
2011-01-11 21:33:11 *Tunnelblick
client.up.tunnelblick.sh: Saved the
DNS and WINS configurations for later use
2011-01-11 21:33:11 *Tunnelblick
client.up.tunnelblick.sh: Set up to
monitor system configuration with leasewatch
2011-01-11 21:33:11 *Tunnelblick: Flushed the DNS cache
2011-01-11 21:33:16 *Tunnelblick leasewatch: A system configuration
change was ignored because it was not relevant
Any idea what could be happening? It seemed to work fine before on
10.4, are there any known issues with 10.6? BTW - I have "Monitor
Connection" checked. If I uncheck it, my connection goes dead, and
stays dead, no reconnect attempts are made by tunnelblick....