Skip to content

Instantly share code, notes, and snippets.

@lamnk
Last active July 25, 2024 10:36
Show Gist options
  • Save lamnk/c499c2d7614b73aabe1c20ed134e9320 to your computer and use it in GitHub Desktop.
Save lamnk/c499c2d7614b73aabe1c20ed134e9320 to your computer and use it in GitHub Desktop.
*Tunnelblick: macOS 14.5 (23F79); Tunnelblick 3.8.6beta05 (build 5706); prior version 3.8.4beta06 (build 5580); Admin user
git commit 520e718a22c48ff2cdbcb075a200a8af406c25cb
The Tunnelblick.app process is not being translated (x86_64)
System Integrity Protection is enabled
Configuration master-UDP4-1194
"Sanitized" condensed configuration file for /Library/Application Support/Tunnelblick/Shared/master-UDP4-1194.tblk:
dev tun
persist-tun
persist-key
cipher AES-128-CBC
ncp-ciphers AES-128-GCM
auth SHA256
tls-client
client
resolv-retry infinite
remote 103.229.193.88 1194 udp
auth-user-pass
ca master-UDP4-1194-ca.crt
tls-auth master-UDP4-1194-tls.key 1
remote-cert-tls server
compress
================================================================================
Files in master-UDP4-1194.tblk:
Contents/Resources/mas….key
Contents/Resources/mas….crt
Contents/Resources/config.ovpn
================================================================================
Tunnelblick Kext Policy Data:
================================================================================
Configuration preferences:
-skipWarningThatNotUsingSpecifiedOpenVPN = 1
-keychainHasUsernameAndPassword = 1
-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 1
-loginWindowSecurityTokenCheckboxIsChecked = 0
-lastConnectionSucceeded = 1
================================================================================
Wildcard preferences:
-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 1
================================================================================
Program preferences:
skipWarningAboutDnsProblems = 1
launchAtNextLogin = 1
tunnelblickVersionHistory = (
"3.8.6beta05 (build 5706)",
"3.8.4beta06 (build 5580)",
"3.8.3beta01 (build 5490)"
)
statusDisplayNumber = 0
lastLaunchTime = 743596123.833406
lastLanguageAtLaunchWasRTL = 0
connectionWindowDisplayCriteria = showWhenConnecting
maxLogDisplaySize = 102400
lastConnectedDisplayName = master-UDP4-1194
keyboardShortcutIndex = 1
updateCheckAutomatically = 0
NSWindow Frame ConnectingWindow = 1525 898 389 217 0 0 3440 1415
NSWindow Frame SUUpdateAlert = 410 363 620 392 0 0 1440 877
detailsWindowFrameVersion = 5706
detailsWindowFrame = {{1354, 588}, {760, 530}}
detailsWindowLeftFrame = {{0, 0}, {136, 410}}
detailsWindowViewIndex = 0
detailsWindowConfigurationsTabIdentifier = log
leftNavSelectedDisplayName = master-UDP4-1194
haveDealtWithOldTunTapPreferences = 1
haveDealtWithAlwaysShowLoginWindow = 1
haveDealtWithOldLoginItem = 1
haveDealtWithAfterDisconnect = 1
SUEnableAutomaticChecks = 0
SUScheduledCheckInterval = 86400
SULastCheckTime = 2020-10-21 10:26:31 +0000
SUHasLaunchedBefore = 1
================================================================================
Forced preferences:
(None)
================================================================================
Deployed forced preferences:
(None)
================================================================================
Tunnelblick Log:
2024-07-25 17:28:46.737739 *Tunnelblick: macOS 14.5 (23F79); Tunnelblick 3.8.6beta05 (build 5706); prior version 3.8.4beta06 (build 5580)
2024-07-25 17:28:47.066872 *Tunnelblick: Attempting connection with master-UDP4-1194; Set nameserver = 769; monitoring connection
2024-07-25 17:28:47.067065 *Tunnelblick: openvpnstart start master-UDP4-1194.tblk 50389 769 0 3 0 34652464 -ptADGNWradsgnw 2.5.3-openssl-1.1.1k
2024-07-25 17:28:47.094528 *Tunnelblick: openvpnstart starting OpenVPN
2024-07-25 17:28:48.251731 Note: Treating option '--ncp-ciphers' as '--data-ciphers' (renamed in OpenVPN 2.5).
2024-07-25 17:28:48.252285 DEPRECATED OPTION: --cipher set to 'AES-128-CBC' but missing in --data-ciphers (AES-128-GCM). Future OpenVPN version will ignore --cipher for cipher negotiations. Add 'AES-128-CBC' to --data-ciphers or change --cipher 'AES-128-CBC' to --data-ciphers-fallback 'AES-128-CBC' to silence this warning.
2024-07-25 17:28:48.254013 OpenVPN 2.5.3 x86_64-apple-darwin [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [MH/RECVDA] [AEAD] built on Jun 26 2021
2024-07-25 17:28:48.254061 library versions: OpenSSL 1.1.1k 25 Mar 2021, LZO 2.10
2024-07-25 17:28:48.256430 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:50389
2024-07-25 17:28:48.256483 Need hold release from management interface, waiting...
2024-07-25 17:28:49.611343 *Tunnelblick: openvpnstart log:
OpenVPN started successfully.
Command used to start OpenVPN (one argument per displayed line):
/Applications/Tunnelblick.app/Contents/Resources/openvpn/openvpn-2.5.3-openssl-1.1.1k/openvpn
--daemon
--log /Library/Application Support/Tunnelblick/Logs/-SLibrary-SApplication Support-STunnelblick-SShared-Smaster--UDP4--1194.tblk-SContents-SResources-Sconfig.ovpn.769_0_3_0_34652464.50389.openvpn.log
--cd /Library/Application Support/Tunnelblick/Shared/master-UDP4-1194.tblk/Contents/Resources
--machine-readable-output
--setenv IV_GUI_VER "net.tunnelblick.tunnelblick 5706 3.8.6beta05 (build 5706)"
--verb 3
--config /Library/Application Support/Tunnelblick/Shared/master-UDP4-1194.tblk/Contents/Resources/config.ovpn
--setenv TUNNELBLICK_CONFIG_FOLDER /Library/Application Support/Tunnelblick/Shared/master-UDP4-1194.tblk/Contents/Resources
--verb 3
--cd /Library/Application Support/Tunnelblick/Shared/master-UDP4-1194.tblk/Contents/Resources
--management 127.0.0.1 50389 /Library/Application Support/Tunnelblick/gblghldjnhcmdlakgpfgilkmjhkfemmaiigdngli.mip
--management-query-passwords
--management-hold
--script-security 2
--route-up /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw
--down /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw
2024-07-25 17:28:49.616013 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:50389
2024-07-25 17:28:49.691419 *Tunnelblick: Established communication with OpenVPN
2024-07-25 17:28:49.701964 MANAGEMENT: CMD 'pid'
2024-07-25 17:28:49.702026 MANAGEMENT: CMD 'auth-retry interact'
2024-07-25 17:28:49.702257 MANAGEMENT: CMD 'state on'
2024-07-25 17:28:49.702393 MANAGEMENT: CMD 'state'
2024-07-25 17:28:49.702462 MANAGEMENT: CMD 'bytecount 1'
2024-07-25 17:28:49.706007 *Tunnelblick: >INFO:OpenVPN Management Interface Version 3 -- type 'help' for more info
2024-07-25 17:28:49.706516 MANAGEMENT: CMD 'hold release'
2024-07-25 17:28:49.737817 *Tunnelblick: Obtained VPN username and password from the Keychain
2024-07-25 17:28:49.738530 MANAGEMENT: CMD 'username "Auth" "kylam"'
2024-07-25 17:28:49.738572 MANAGEMENT: CMD 'password [...]'
2024-07-25 17:28:49.738849 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2024-07-25 17:28:49.741671 Outgoing Control Channel Authentication: Using 256 bit message hash 'SHA256' for HMAC authentication
2024-07-25 17:28:49.741699 Incoming Control Channel Authentication: Using 256 bit message hash 'SHA256' for HMAC authentication
2024-07-25 17:28:49.743321 TCP/UDP: Preserving recently used remote address: [AF_INET]103.229.193.88:1194
2024-07-25 17:28:49.743396 Socket Buffers: R=[786896->786896] S=[9216->9216]
2024-07-25 17:28:49.743438 UDP link local (bound): [AF_INET][undef]:1194
2024-07-25 17:28:49.743452 UDP link remote: [AF_INET]103.229.193.88:1194
2024-07-25 17:28:49.743509 MANAGEMENT: >STATE:1721903329,WAIT,,,,,,
2024-07-25 17:28:50.051198 MANAGEMENT: >STATE:1721903330,AUTH,,,,,,
2024-07-25 17:28:50.051307 TLS: Initial packet from [AF_INET]103.229.193.88:1194, sid=860d56d1 d2e9b976
2024-07-25 17:28:50.246237 VERIFY OK: depth=1, C=VN, ST=HCMC, L=HCMC, O=XuyenViet, [email protected], CN=internal-ca, OU=IT
2024-07-25 17:28:50.246948 VERIFY KU OK
2024-07-25 17:28:50.247006 Validating certificate extended key usage
2024-07-25 17:28:50.247031 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
2024-07-25 17:28:50.247045 VERIFY EKU OK
2024-07-25 17:28:50.247057 VERIFY OK: depth=0, C=VN, ST=HCMC, L=HCMC, O=XuyenViet, [email protected], CN=*.otosaigon.com, OU=IT, subjectAltName=
2024-07-25 17:28:50.562578 Control Channel: TLSv1.2, cipher TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384, peer certificate: 2048 bit RSA, signature: RSA-SHA256
2024-07-25 17:28:50.562666 [*.otosaigon.com] Peer Connection Initiated with [AF_INET]103.229.193.88:1194
2024-07-25 17:28:51.648815 MANAGEMENT: >STATE:1721903331,GET_CONFIG,,,,,,
2024-07-25 17:28:51.648943 SENT CONTROL [*.otosaigon.com]: 'PUSH_REQUEST' (status=1)
2024-07-25 17:28:57.005221 SENT CONTROL [*.otosaigon.com]: 'PUSH_REQUEST' (status=1)
2024-07-25 17:28:57.026451 PUSH: Received control message: 'PUSH_REPLY,route 192.168.116.0 255.255.255.0,route-gateway 10.16.116.1,topology subnet,ping 10,ping-restart 60,ifconfig 10.16.116.6 255.255.255.0,peer-id 0'
2024-07-25 17:28:57.026604 OPTIONS IMPORT: timers and/or timeouts modified
2024-07-25 17:28:57.026655 OPTIONS IMPORT: --ifconfig/up options modified
2024-07-25 17:28:57.026671 OPTIONS IMPORT: route options modified
2024-07-25 17:28:57.026687 OPTIONS IMPORT: route-related options modified
2024-07-25 17:28:57.026702 OPTIONS IMPORT: peer-id set
2024-07-25 17:28:57.026716 OPTIONS IMPORT: adjusting link_mtu to 1625
2024-07-25 17:28:57.026733 Using peer cipher 'AES-128-CBC'
2024-07-25 17:28:57.027008 Outgoing Data Channel: Cipher 'AES-128-CBC' initialized with 128 bit key
2024-07-25 17:28:57.027088 Outgoing Data Channel: Using 256 bit message hash 'SHA256' for HMAC authentication
2024-07-25 17:28:57.027135 Incoming Data Channel: Cipher 'AES-128-CBC' initialized with 128 bit key
2024-07-25 17:28:57.027152 Incoming Data Channel: Using 256 bit message hash 'SHA256' for HMAC authentication
2024-07-25 17:28:57.028390 Opened utun device utun6
2024-07-25 17:28:57.028518 MANAGEMENT: >STATE:1721903337,ASSIGN_IP,,10.16.116.6,,,,
2024-07-25 17:28:57.028633 /sbin/ifconfig utun6 delete
ifconfig: ioctl (SIOCDIFADDR): Can't assign requested address
2024-07-25 17:28:57.087248 NOTE: Tried to delete pre-existing tun/tap instance -- No Problem if failure
2024-07-25 17:28:57.087320 /sbin/ifconfig utun6 10.16.116.6 10.16.116.6 netmask 255.255.255.0 mtu 1500 up
2024-07-25 17:28:57.090485 /sbin/route add -net 10.16.116.0 10.16.116.6 255.255.255.0
add net 10.16.116.0: gateway 10.16.116.6
2024-07-25 17:28:57.099674 MANAGEMENT: >STATE:1721903337,ADD_ROUTES,,,,,,
2024-07-25 17:28:57.099723 /sbin/route add -net 192.168.116.0 10.16.116.1 255.255.255.0
add net 192.168.116.0: gateway 10.16.116.1
17:28:57 *Tunnelblick: **********************************************
17:28:57 *Tunnelblick: Start of output from client.up.tunnelblick.sh
17:28:59 *Tunnelblick: NOTE: No network configuration changes need to be made.
17:28:59 *Tunnelblick: WARNING: Will NOT monitor for other network configuration changes.
17:28:59 *Tunnelblick: WARNING: Will NOT disable IPv6 settings.
17:28:59 *Tunnelblick: DNS servers '192.168.0.1' will be used for DNS queries when the VPN is active
17:28:59 *Tunnelblick: NOTE: The DNS servers do not include any free public DNS servers known to Tunnelblick. This may cause DNS queries to fail or be intercepted or falsified even if they are directed through the VPN. Specify only known public DNS servers or DNS servers located on the VPN network to avoid such problems.
17:28:59 *Tunnelblick: Flushed the DNS cache via dscacheutil
17:28:59 *Tunnelblick: /usr/sbin/discoveryutil not present. Not flushing the DNS cache via discoveryutil
17:28:59 *Tunnelblick: Notified mDNSResponder that the DNS cache was flushed
17:28:59 *Tunnelblick: Notified mDNSResponderHelper that the DNS cache was flushed
17:28:59 *Tunnelblick: End of output from client.up.tunnelblick.sh
17:28:59 *Tunnelblick: **********************************************
2024-07-25 17:28:59.659747 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
2024-07-25 17:28:59.659781 Initialization Sequence Completed
2024-07-25 17:28:59.659814 MANAGEMENT: >STATE:1721903339,CONNECTED,SUCCESS,10.16.116.6,103.229.193.88,1194,,
2024-07-25 17:29:00.878026 *Tunnelblick: Routing info stdout:
route to: 192.168.0.1
destination: 192.168.0.1
interface: en0
flags: <UP,HOST,DONE,LLINFO,WASCLONED,IFSCOPE,IFREF,ROUTER>
recvpipe sendpipe ssthresh rtt,msec rttvar hopcount mtu expire
0 0 0 0 0 0 1500 1187
stderr:
2024-07-25 17:29:00.878425 *Tunnelblick: Warning: DNS server address 192.168.0.1 is not a public IP address and is not being routed through the VPN.
================================================================================
Down log:
16:00:56 *Tunnelblick: **********************************************
16:00:56 *Tunnelblick: Start of output from client.down.tunnelblick.sh
16:00:58 *Tunnelblick: WARNING: Not restoring network settings because no saved Tunnelblick DNS information was found.
16:00:58 *Tunnelblick: Flushed the DNS cache with dscacheutil -flushcache
16:00:58 *Tunnelblick: Notified mDNSResponder that the DNS cache was flushed
16:00:58 *Tunnelblick: End of output from client.down.tunnelblick.sh
16:00:58 *Tunnelblick: **********************************************
================================================================================
Previous down log:
00:14:42 *Tunnelblick: **********************************************
00:14:42 *Tunnelblick: Start of output from client.down.tunnelblick.sh
00:14:43 *Tunnelblick: WARNING: Not restoring network settings because no saved Tunnelblick DNS information was found.
00:14:43 *Tunnelblick: Flushed the DNS cache with dscacheutil -flushcache
00:14:43 *Tunnelblick: Notified mDNSResponder that the DNS cache was flushed
00:14:43 *Tunnelblick: End of output from client.down.tunnelblick.sh
00:14:43 *Tunnelblick: **********************************************
================================================================================
Network services:
An asterisk (*) denotes that a network service is disabled.
USB 10/100/1000 LAN
Wi-Fi
Thunderbolt Bridge
Tailscale Tunnel
Wi-Fi Power (en0): On
================================================================================
ifconfig output:
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
options=1203<RXCSUM,TXCSUM,TXSTATUS,SW_TIMESTAMP>
inet 127.0.0.1 netmask 0xff000000
inet6 ::1 prefixlen 128
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1
nd6 options=201<PERFORMNUD,DAD>
gif0: flags=8010<POINTOPOINT,MULTICAST> mtu 1280
stf0: flags=0<> mtu 1280
en5: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
ether ac:de:48:00:11:22
inet6 fe80::aede:48ff:fe00:1122%en5 prefixlen 64 scopeid 0x4
nd6 options=201<PERFORMNUD,DAD>
media: autoselect (100baseTX <full-duplex>)
status: active
ap1: flags=8802<BROADCAST,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether a6:83:e7:e0:e9:b7
media: autoselect
en3: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=460<TSO4,TSO6,CHANNEL_IO>
ether 82:82:58:ca:04:05
media: autoselect <full-duplex>
status: inactive
en1: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=460<TSO4,TSO6,CHANNEL_IO>
ether 82:82:58:ca:04:01
media: autoselect <full-duplex>
status: inactive
en2: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=460<TSO4,TSO6,CHANNEL_IO>
ether 82:82:58:ca:04:00
media: autoselect <full-duplex>
status: inactive
en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=6460<TSO4,TSO6,CHANNEL_IO,PARTIAL_CSUM,ZEROINVERT_CSUM>
ether a4:83:e7:e0:e9:b7
inet6 fe80::e9:85cf:f218:fc68%en0 prefixlen 64 secured scopeid 0x9
inet 192.168.0.146 netmask 0xffffff00 broadcast 192.168.0.255
nd6 options=201<PERFORMNUD,DAD>
media: autoselect
status: active
en4: flags=8963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1500
options=460<TSO4,TSO6,CHANNEL_IO>
ether 82:82:58:ca:04:04
media: autoselect <full-duplex>
status: inactive
awdl0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=6460<TSO4,TSO6,CHANNEL_IO,PARTIAL_CSUM,ZEROINVERT_CSUM>
ether c6:22:fe:05:88:da
inet6 fe80::c422:feff:fe05:88da%awdl0 prefixlen 64 scopeid 0xb
nd6 options=201<PERFORMNUD,DAD>
media: autoselect
status: active
llw0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=400<CHANNEL_IO>
ether c6:22:fe:05:88:da
inet6 fe80::c422:feff:fe05:88da%llw0 prefixlen 64 scopeid 0xc
nd6 options=201<PERFORMNUD,DAD>
media: autoselect
status: inactive
bridge0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=63<RXCSUM,TXCSUM,TSO4,TSO6>
ether 82:82:58:ca:04:01
Configuration:
id 0:0:0:0:0:0 priority 0 hellotime 0 fwddelay 0
maxage 0 holdcnt 0 proto stp maxaddr 100 timeout 1200
root id 0:0:0:0:0:0 priority 0 ifcost 0 port 0
ipfilter disabled flags 0x0
member: en1 flags=3<LEARNING,DISCOVER>
ifmaxaddr 0 port 7 priority 0 path cost 0
member: en2 flags=3<LEARNING,DISCOVER>
ifmaxaddr 0 port 8 priority 0 path cost 0
member: en3 flags=3<LEARNING,DISCOVER>
ifmaxaddr 0 port 6 priority 0 path cost 0
member: en4 flags=3<LEARNING,DISCOVER>
ifmaxaddr 0 port 10 priority 0 path cost 0
nd6 options=201<PERFORMNUD,DAD>
media: <unknown type>
status: inactive
utun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1500
inet6 fe80::2516:47af:70c4:cce%utun0 prefixlen 64 scopeid 0xe
nd6 options=201<PERFORMNUD,DAD>
utun1: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1380
inet6 fe80::a058:f565:431:94b%utun1 prefixlen 64 scopeid 0xf
nd6 options=201<PERFORMNUD,DAD>
utun2: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 2000
inet6 fe80::4070:be67:c852:a0ef%utun2 prefixlen 64 scopeid 0x10
nd6 options=201<PERFORMNUD,DAD>
utun3: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1000
inet6 fe80::ce81:b1c:bd2c:69e%utun3 prefixlen 64 scopeid 0x11
nd6 options=201<PERFORMNUD,DAD>
utun4: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1380
inet6 fe80::63af:b667:d8e8:ec62%utun4 prefixlen 64 scopeid 0x12
nd6 options=201<PERFORMNUD,DAD>
utun5: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1380
inet6 fe80::8b1a:ddbd:9234:4151%utun5 prefixlen 64 scopeid 0x13
nd6 options=201<PERFORMNUD,DAD>
utun6: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1500
inet 10.16.116.6 --> 10.16.116.6 netmask 0xffffff00
================================================================================
Non-Apple kexts that are loaded:
Index Refs Address Size Wired Name (Version) UUID <Linked Against>
================================================================================
Quit Log:
2024-07-24 11:13:37.737162 applicationShouldTerminate: termination because of Quit; delayed until 'shutdownTunnelblick' finishes)
2024-07-24 11:13:37.741897 shutDownTunnelblick: started.
2024-07-24 11:13:37.743828 shutDownTunnelblick: Starting cleanup.
2024-07-24 11:13:37.745181 cleanup: Entering cleanup
2024-07-24 11:13:37.745563 synchronized user defaults
2024-07-24 11:13:39.483380 shutDownTunnelblick: Cleanup finished.
2024-07-24 11:13:39.483876 Finished shutting down Tunnelblick; allowing termination
================================================================================
Console Log:
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment