Mac Os Sierra - impossible to connect after loosing connexion once

127 views
Skip to first unread message

Victor Parpoil

unread,
Jul 9, 2018, 6:54:18 AM7/9/18
to tunnelblick-discuss
Tunnelblick 3.7.6a (build 5080)

Hello, 
I am facing a severe issue with mac os Sierra. 
I can connect to my VPN right after a reboot. Then, if I loose my connection (because of sleep mode, of because my connexion is unstable and then I switch from wifi to the wifi of my phone, using thethering), I am unable to reconnect to the VPN (even manually).
Sometimes I can see a loop of disconnecting / reconnecting in the pop over window in the top right. 
Usually when this happens, Tunnelblick uses 100% of my CPU and my only option is to kill it.
I end up rebooting my computer way too often in order to connect to my VPN...

Here is the log, I hope it will help to fix. 
output.txt

Tunnelblick developer

unread,
Jul 9, 2018, 6:59:29 AM7/9/18
to tunnelbli...@googlegroups.com
Try removing the "user nobody" and "group nogroup" lines in your OpenVPN configuration file.

Including those OpenVPN options causes OpenVPN to run without privileges after it sets up the VPN, so it is unable to do the routing commands that are needed to restart the VPN.


[Edited 2018-07-09 07:00 AM UTC-4 to change "nobody" to "nogroup".]

Victor Parpoil

unread,
Jul 9, 2018, 10:22:39 AM7/9/18
to tunnelblick-discuss
Hi, 
Thanks a lot for your answer. I just tried and saw some differences in the log. It did solve my issue : I don't have to reboot my computer to make it work, only had to kill tunnelblick a few times because it was stuck in the reconnection loop, and then I can connect again without reboot! 
Thank you very much. Here is the log in case it helps to debug a bit more.


*Tunnelblick: OS X 10.12.6; Tunnelblick 3.7.6a (build 5080); prior version 3.7.6 (build 5060)

2018-07-09 16:15:39 *Tunnelblick: Established communication with OpenVPN

2018-07-09 16:15:41 *Tunnelblick: Disconnecting; notification window disconnect button pressed

                                         16:15:40 2018 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

2018-07-09 16:12:34 *Tunnelblick: openvpnstart starting OpenVPN

2018-07-09 16:12:51 *Tunnelblick process-network-changes: A system configuration change was ignored

2018-07-09 16:13:28 *Tunnelblick process-network-changes: ServerAddresses changed from

                    *                    <array> {

                    *                    0 : 208.67.222.222

                    *                    1 : 208.67.220.220

                    *                    }

                    *                     to

                    *                    

                    *                    pre-VPN was

                    *                    <array> {

                    *                    0 : 8.8.8.8

                    *                    1 : 8.8.4.4

                    *                    }

2018-07-09 16:13:28 *Tunnelblick process-network-changes: SearchDomains changed from

                    *                    <array> {

                    *                    0 : openvpn

                    *                    }

                    *                     to (pre-VPN)

                    *                    

2018-07-09 16:13:28 *Tunnelblick process-network-changes: DomainName changed from

                    *                    openvpn

                    *                     to

                    *                    

                    *                    pre-VPN was

                    *                    lan

2018-07-09 16:13:28 *Tunnelblick process-network-changes: WINSAddresses changed from

                    *                    <array> {

                    *                    0 : 8.8.2.2

                    *                    }

                    *                     to

                    *                    

                    *                    pre-VPN was

                    *                    <array> {

                    *                    0 : 8.8.2.2

                    *                    }

2018-07-09 16:13:28 *Tunnelblick process-network-changes: ServerAddresses changed; sending USR1 to OpenVPN (process ID 1776) to restart the connection.

2018-07-09 16:13:38 *Tunnelblick process-network-changes: WINSAddresses changed from

                    *                    <array> {

                    *                    0 : 8.8.2.2

                    *                    }

                    *                     to

                    *                    

                    *                    pre-VPN was

                    *                    <array> {

                    *                    0 : 8.8.2.2

                    *                    }

2018-07-09 16:13:38 *Tunnelblick process-network-changes: WINSAddresses changed; sending USR1 to OpenVPN (process ID 1776) to restart the connection.

2018-07-09 16:15:40 TCP/UDP: Preserving recently used remote address: [AF_INET][IP ADDRESS]:443

2018-07-09 16:15:40 Socket Buffers: R=[131072->131072] S=[131072->131072]

2018-07-09 16:15:40 Attempting to establish TCP connection with [AF_INET][IP ADDRESS]:443 [nonblock]

2018-07-09 16:15:40 MANAGEMENT: >STATE:1531145740,TCP_CONNECT,,,,,,

2018-07-09 16:15:40 TCP: connect to [AF_INET][IP ADDRESS]:443 failed: Can't assign requested address

2018-07-09 16:15:40 SIGUSR1[connection failed(soft),init_instance] received, process restarting

2018-07-09 16:15:40 MANAGEMENT: >STATE:1531145740,RECONNECTING,init_instance,,,,,

2018-07-09 16:15:40 MANAGEMENT: CMD 'hold release'

2018-07-09 16:15:40 MANAGEMENT: CMD 'hold release'

2018-07-09 16:15:40 MANAGEMENT: CMD 'hold release'

2018-07-09 16:15:40 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts

2018-07-09 16:15:40 TCP/UDP: Preserving recently used remote address: [AF_INET][IP ADDRESS]:443

2018-07-09 16:15:40 Socket Buffers: R=[131072->131072] S=[131072->131072]

2018-07-09 16:15:40 Attempting to establish TCP connection with [AF_INET][IP ADDRESS]:443 [nonblock]

2018-07-09 16:15:40 MANAGEMENT: >STATE:1531145740,TCP_CONNECT,,,,,,

2018-07-09 16:15:40 TCP: connect to [AF_INET][IP ADDRESS]:443 failed: Can't assign requested address

2018-07-09 16:15:40 SIGUSR1[connection failed(soft),init_instance] received, process restarting

2018-07-09 16:15:40 MANAGEMENT: >STATE:1531145740,RECONNECTING,init_instance,,,,,

2018-07-09 16:15:40 MANAGEMENT: CMD 'hold release'

2018-07-09 16:15:40 MANAGEMENT: CMD 'hold release'



Tunnelblick developer

unread,
Jul 9, 2018, 5:55:08 PM7/9/18
to tunnelblick-discuss
There is some other problem with your setup.

For more help, please post the diagnostic info obtained by following the instructions at Read Before You Post. (That is, as it is failing now, after having removed the "user nouser" and "group nogroup" options.)

Victor Parpoil

unread,
Jul 10, 2018, 3:53:40 AM7/10/18
to tunnelblick-discuss
So here are the steps I followed :
connected to wifi at my office, I connect to VPN
While connected, I change wifi to phone thethering, then I enter an infinite reconnection loop.
I disconnected and went back to office wifi, and then I was able to reconnect (without killing tunnelblick)
Here is the diagnostic info.
Thanks for your help ! 
log.txt
Reply all
Reply to author
Forward
0 new messages