Hey, I followed this guide exactly: https://openwrt.org/docs/guide-user/services/vpn/openvpn/server.setup
But I am unable to successfully connect.
Here is my tmp/openvpn.log
Fri Aug 24 21:01:11 2018 us=424333 OpenVPN 2.4.5 arm-openwrt-linux-gnu [SSL (mbed TLS)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Fri Aug 24 21:01:11 2018 us=424407 library versions: mbed TLS 2.12.0, LZO 2.10
Fri Aug 24 21:01:11 2018 us=424757 Diffie-Hellman initialized with 2048 bit key
Fri Aug 24 21:01:11 2018 us=426144 WARNING: failed to personalise random
Fri Aug 24 21:01:11 2018 us=426387 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Aug 24 21:01:11 2018 us=426438 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Fri Aug 24 21:01:11 2018 us=426487 TLS-Auth MTU parms [ L:1624 D:1182 EF:68 EB:0 ET:0 EL:3 ]
Fri Aug 24 21:01:11 2018 us=427386 TUN/TAP device ovpns0 opened
Fri Aug 24 21:01:11 2018 us=427593 TUN/TAP TX queue length set to 100
Fri Aug 24 21:01:11 2018 us=427660 do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Fri Aug 24 21:01:11 2018 us=427731 /sbin/ifconfig ovpns0 192.168.200.1 netmask 255.255.255.0 mtu 1500 broadcast 192.168.200.255
Fri Aug 24 21:01:11 2018 us=432721 Data Channel MTU parms [ L:1624 D:1450 EF:124 EB:406 ET:0 EL:3 ]
Fri Aug 24 21:01:11 2018 us=432818 Could not determine IPv4/IPv6 protocol. Using AF_INET
Fri Aug 24 21:01:11 2018 us=432872 Socket Buffers: R=[87380->87380] S=[16384->16384]
Fri Aug 24 21:01:11 2018 us=432925 Listening for incoming TCP connection on [AF_INET][undef]:1194
Fri Aug 24 21:01:11 2018 us=432973 TCPv4_SERVER link local (bound): [AF_INET][undef]:1194
Fri Aug 24 21:01:11 2018 us=433011 TCPv4_SERVER link remote: [AF_UNSPEC]
Fri Aug 24 21:01:11 2018 us=433052 MULTI: multi_init called, r=256 v=256
Fri Aug 24 21:01:11 2018 us=433111 IFCONFIG POOL: base=192.168.200.2 size=252, ipv6=0
Fri Aug 24 21:01:11 2018 us=433190 MULTI: TCP INIT maxclients=1024 maxevents=1028
Fri Aug 24 21:01:11 2018 us=433303 Initialization Sequence Completed
Options error: Unrecognized option or missing or extra parameter(s) in openvpn-VPNserver.conf:16: pkcs12 (2.4.5)
Use --help for more information.
Here is my client log (using Tunnelblick on MacOS):
*Tunnelblick: OS X 10.13.6; Tunnelblick 3.7.6a (build 5080); Admin user
git commit 6fdd1f713d2f62963325336c09e74808321191cb
Configuration Nicknamelan
"Sanitized" condensed configuration file for /Library/Application Support/Tunnelblick/Shared/Nicknamelan.tblk:
client
dev tun
proto udp
fast-io
remote xx.xxx.xx.xx 1194
remote-cert-tls server
nobind
persist-key
persist-tun
compress lzo
verb 3
key-direction 1
pull-filter ignore "block-outside-dns"
<ca>
[Security-related line(s) omitted]
</ca>
<cert>
[Security-related line(s) omitted]
</cert>
<key>
[Security-related line(s) omitted]
</key>
<tls-auth>
[Security-related line(s) omitted]
</tls-auth>
================================================================================
Non-Apple kexts that are loaded:
================================================================================
There are no unusual files in Nicknamelan.tblk
================================================================================
Configuration preferences:
-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0
-loggingLevel = 7
-lastConnectionSucceeded = 0
================================================================================
Wildcard preferences:
-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0
================================================================================
Program preferences:
launchAtNextLogin = 1
tunnelblickVersionHistory = (
"3.7.6a (build 5080)"
)
lastLaunchTime = 556862591.8539391
lastLanguageAtLaunchWasRTL = 0
connectionWindowDisplayCriteria = showWhenConnecting
maxLogDisplaySize = 102400
keyboardShortcutIndex = 1
updateCheckAutomatically = 1
NSWindow Frame ConnectingWindow = 525 518 389 187 0 0 1440 878
detailsWindowFrameVersion = 5080
detailsWindowFrame = {{191, 286}, {920, 468}}
detailsWindowLeftFrame = {{0, 0}, {165, 350}}
detailsWindowViewIndex = 0
detailsWindowConfigurationsTabIdentifier = log
leftNavSelectedDisplayName = Nicknamelan
AdvancedWindowTabIdentifier = connectingAndDisconnecting
haveDealtWithOldTunTapPreferences = 1
haveDealtWithOldLoginItem = 1
haveDealtWithAfterDisconnect = 1
SUEnableAutomaticChecks = 1
SUScheduledCheckInterval = 86400
SULastCheckTime = 2018-08-25 04:03:12 +0000
SUHasLaunchedBefore = 1
WebKitDefaultFontSize = 16
WebKitStandardFont = Times
================================================================================
Tunnelblick Log:
*Tunnelblick: OS X 10.13.6; Tunnelblick 3.7.6a (build 5080)
2018-08-24 21:03:53 *Tunnelblick: Attempting connection with Nicknamelan; Set nameserver = 1793; monitoring connection
2018-08-24 21:03:53 *Tunnelblick: openvpnstart start Nicknamelan.tblk 60499 1793 0 3 0 1065264 -ptADGNWradsgnw 2.4.6-openssl-1.0.2o
2018-08-24 21:03:53 NOTE: debug verbosity (--verb 7) is enabled but this build lacks debug support.
2018-08-24 21:03:53 NOTE: debug verbosity (--verb 7) is enabled but this build lacks debug support.
2018-08-24 21:03:53 us=981867 Current Parameter Settings:
2018-08-24 21:03:53 us=981921 config = '/Library/Application Support/Tunnelblick/Shared/Nicknamelan.tblk/Contents/Resources/config.ovpn'
2018-08-24 21:03:53 us=981941 mode = 0
2018-08-24 21:03:53 us=981956 show_ciphers = DISABLED
2018-08-24 21:03:53 us=981970 show_digests = DISABLED
2018-08-24 21:03:53 us=981984 show_engines = DISABLED
2018-08-24 21:03:53 us=981997 genkey = DISABLED
2018-08-24 21:03:53 us=982011 key_pass_file = '[UNDEF]'
2018-08-24 21:03:53 us=982025 show_tls_ciphers = DISABLED
2018-08-24 21:03:53 us=982038 connect_retry_max = 0
2018-08-24 21:03:53 us=982052 Connection profiles [0]:
2018-08-24 21:03:53 us=982066 proto = udp
2018-08-24 21:03:53 us=982079 local = '[UNDEF]'
2018-08-24 21:03:53 us=982093 local_port = '[UNDEF]'
2018-08-24 21:03:53 us=982106 remote = 'xx.xxx.xx.xx'
2018-08-24 21:03:53 us=982120 remote_port = '1194'
2018-08-24 21:03:53 us=982134 remote_float = DISABLED
2018-08-24 21:03:53 us=982147 bind_defined = DISABLED
2018-08-24 21:03:53 us=982161 bind_local = DISABLED
2018-08-24 21:03:53 us=982174 bind_ipv6_only = DISABLED
2018-08-24 21:03:53 us=982187 connect_retry_seconds = 5
2018-08-24 21:03:53 us=982201 connect_timeout = 120
2018-08-24 21:03:53 us=982215 xormethod = 0
2018-08-24 21:03:53 us=982228 xormask = ''
2018-08-24 21:03:53 us=982242 xormasklen = 0
2018-08-24 21:03:53 us=982255 socks_proxy_server = '[UNDEF]'
2018-08-24 21:03:53 us=982269 socks_proxy_port = '[UNDEF]'
2018-08-24 21:03:53 us=982283 tun_mtu = 1500
2018-08-24 21:03:53 us=982296 tun_mtu_defined = ENABLED
2018-08-24 21:03:53 us=982309 link_mtu = 1500
2018-08-24 21:03:53 us=982323 link_mtu_defined = DISABLED
2018-08-24 21:03:53 us=982336 tun_mtu_extra = 0
2018-08-24 21:03:53 us=982350 tun_mtu_extra_defined = DISABLED
2018-08-24 21:03:53 us=982363 mtu_discover_type = -1
2018-08-24 21:03:53 us=982377 fragment = 0
2018-08-24 21:03:53 us=982390 mssfix = 1450
2018-08-24 21:03:53 us=982403 explicit_exit_notification = 0
2018-08-24 21:03:53 us=982417 Connection profiles END
2018-08-24 21:03:53 us=982430 remote_random = DISABLED
2018-08-24 21:03:53 us=982444 ipchange = '[UNDEF]'
2018-08-24 21:03:53 us=982457 dev = 'tun'
2018-08-24 21:03:53 us=982471 dev_type = '[UNDEF]'
2018-08-24 21:03:53 us=982484 dev_node = '[UNDEF]'
2018-08-24 21:03:53 us=982498 lladdr = '[UNDEF]'
2018-08-24 21:03:53 us=982511 topology = 1
2018-08-24 21:03:53 us=982524 ifconfig_local = '[UNDEF]'
2018-08-24 21:03:53 us=982538 ifconfig_remote_netmask = '[UNDEF]'
2018-08-24 21:03:53 us=982551 ifconfig_noexec = DISABLED
2018-08-24 21:03:53 us=982565 ifconfig_nowarn = DISABLED
2018-08-24 21:03:53 us=982578 ifconfig_ipv6_local = '[UNDEF]'
2018-08-24 21:03:53 us=982591 ifconfig_ipv6_netbits = 0
2018-08-24 21:03:53 us=982605 ifconfig_ipv6_remote = '[UNDEF]'
2018-08-24 21:03:53 us=982618 shaper = 0
2018-08-24 21:03:53 us=982631 mtu_test = 0
2018-08-24 21:03:53 us=982644 mlock = DISABLED
2018-08-24 21:03:53 us=982657 keepalive_ping = 0
2018-08-24 21:03:53 us=982671 keepalive_timeout = 0
2018-08-24 21:03:53 us=982683 inactivity_timeout = 0
2018-08-24 21:03:53 us=982696 ping_send_timeout = 0
2018-08-24 21:03:53 us=982709 ping_rec_timeout = 0
2018-08-24 21:03:53 us=982723 ping_rec_timeout_action = 0
2018-08-24 21:03:53 us=982735 ping_timer_remote = DISABLED
2018-08-24 21:03:53 us=982749 remap_sigusr1 = 0
2018-08-24 21:03:53 us=982762 persist_tun = ENABLED
2018-08-24 21:03:53 us=982775 persist_local_ip = DISABLED
2018-08-24 21:03:53 us=982817 persist_remote_ip = DISABLED
2018-08-24 21:03:53 us=982838 persist_key = ENABLED
2018-08-24 21:03:53 us=982853 passtos = DISABLED
2018-08-24 21:03:53 us=982866 resolve_retry_seconds = 1000000000
2018-08-24 21:03:53 us=982880 resolve_in_advance = DISABLED
2018-08-24 21:03:53 us=982893 username = '[UNDEF]'
2018-08-24 21:03:53 us=982906 groupname = '[UNDEF]'
2018-08-24 21:03:53 us=982919 chroot_dir = '[UNDEF]'
2018-08-24 21:03:53 us=982933 cd_dir = '/Library/Application Support/Tunnelblick/Shared/Nicknamelan.tblk/Contents/Resources'
2018-08-24 21:03:53 us=982947 writepid = '[UNDEF]'
2018-08-24 21:03:53 us=982960 up_script = '/Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw'
2018-08-24 21:03:53 us=982974 down_script = '/Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw'
2018-08-24 21:03:53 us=982987 down_pre = DISABLED
2018-08-24 21:03:53 us=983000 up_restart = DISABLED
2018-08-24 21:03:53 us=983039 up_delay = DISABLED
2018-08-24 21:03:53 us=983053 daemon = ENABLED
2018-08-24 21:03:53 us=983066 inetd = 0
2018-08-24 21:03:53 us=983079 log = ENABLED
2018-08-24 21:03:53 us=983092 suppress_timestamps = DISABLED
2018-08-24 21:03:53 us=983106 machine_readable_output = DISABLED
2018-08-24 21:03:53 us=983119 nice = 0
2018-08-24 21:03:53 us=983132 verbosity = 7
2018-08-24 21:03:53 us=983145 mute = 0
2018-08-24 21:03:53 us=983159 status_file = '[UNDEF]'
2018-08-24 21:03:53 us=983172 status_file_version = 1
2018-08-24 21:03:53 us=983185 status_file_update_freq = 60
2018-08-24 21:03:53 us=983198 occ = ENABLED
2018-08-24 21:03:53 us=983212 rcvbuf = 0
2018-08-24 21:03:53 us=983225 sndbuf = 0
2018-08-24 21:03:53 us=983238 sockflags = 0
2018-08-24 21:03:53 us=983260 fast_io = ENABLED
2018-08-24 21:03:53 us=983274 comp.alg = 2
2018-08-24 21:03:53 us=983287 comp.flags = 0
2018-08-24 21:03:53 us=983303 route_script = '[UNDEF]'
2018-08-24 21:03:53 us=983317 route_default_gateway = '[UNDEF]'
2018-08-24 21:03:53 us=983331 route_default_metric = 0
2018-08-24 21:03:53 us=983345 route_noexec = DISABLED
2018-08-24 21:03:53 us=983359 route_delay = 0
2018-08-24 21:03:53 us=983373 route_delay_window = 30
2018-08-24 21:03:53 us=983387 route_delay_defined = DISABLED
2018-08-24 21:03:53 us=983402 route_nopull = DISABLED
2018-08-24 21:03:53 us=983416 route_gateway_via_dhcp = DISABLED
2018-08-24 21:03:53 us=983430 allow_pull_fqdn = DISABLED
2018-08-24 21:03:53 us=983444 Pull filters:
2018-08-24 21:03:53 us=983458 ignore "block-outside-dns"
2018-08-24 21:03:53 us=983471 management_addr = '127.0.0.1'
2018-08-24 21:03:53 us=983485 management_port = '60499'
2018-08-24 21:03:53 us=983499 management_user_pass = '/Library/Application Support/Tunnelblick/bbpgcegiaikmcpdfgokkapbhdallpenkebbipnie.mip'
2018-08-24 21:03:53 us=983513 management_log_history_cache = 250
2018-08-24 21:03:53 us=983527 management_echo_buffer_size = 100
2018-08-24 21:03:53 us=983541 management_write_peer_info_file = '[UNDEF]'
2018-08-24 21:03:53 us=983557 management_client_user = '[UNDEF]'
2018-08-24 21:03:53 us=983571 management_client_group = '[UNDEF]'
2018-08-24 21:03:53 us=983585 management_flags = 6
2018-08-24 21:03:53 us=983598 shared_secret_file = '[UNDEF]'
2018-08-24 21:03:53 us=983619 key_direction = 1
2018-08-24 21:03:53 us=983633 ciphername = 'BF-CBC'
2018-08-24 21:03:53 us=983646 ncp_enabled = ENABLED
2018-08-24 21:03:53 us=983660 ncp_ciphers = 'AES-256-GCM:AES-128-GCM'
2018-08-24 21:03:53 us=983675 authname = 'SHA1'
2018-08-24 21:03:53 us=983689 prng_hash = 'SHA1'
2018-08-24 21:03:53 us=983704 prng_nonce_secret_len = 16
2018-08-24 21:03:53 us=983739 keysize = 0
2018-08-24 21:03:53 us=983753 engine = DISABLED
2018-08-24 21:03:53 us=983767 replay = ENABLED
2018-08-24 21:03:53 us=983785 mute_replay_warnings = DISABLED
2018-08-24 21:03:53 us=983800 replay_window = 64
2018-08-24 21:03:53 us=983814 replay_time = 15
2018-08-24 21:03:53 us=983834 packet_id_file = '[UNDEF]'
2018-08-24 21:03:53 us=983853 use_iv = ENABLED
2018-08-24 21:03:53 us=983867 test_crypto = DISABLED
2018-08-24 21:03:53 us=983881 tls_server = DISABLED
2018-08-24 21:03:53 us=983895 tls_client = ENABLED
2018-08-24 21:03:53 us=983908 key_method = 2
2018-08-24 21:03:53 us=983925 ca_file = '[[INLINE]]'
2018-08-24 21:03:53 us=983939 ca_path = '[UNDEF]'
2018-08-24 21:03:53 us=983978 dh_file = '[UNDEF]'
2018-08-24 21:03:53 us=983993 cert_file = '[[INLINE]]'
2018-08-24 21:03:53 us=984006 extra_certs_file = '[UNDEF]'
2018-08-24 21:03:53 us=984109 priv_key_file = '[[INLINE]]'
2018-08-24 21:03:53 us=984160 pkcs12_file = '[UNDEF]'
2018-08-24 21:03:53 us=984174 cipher_list = '[UNDEF]'
2018-08-24 21:03:53 us=984186 tls_cert_profile = '[UNDEF]'
2018-08-24 21:03:53 us=984197 tls_verify = '[UNDEF]'
2018-08-24 21:03:53 us=984213 tls_export_cert = '[UNDEF]'
2018-08-24 21:03:53 us=984225 verify_x509_type = 0
2018-08-24 21:03:53 us=984240 verify_x509_name = '[UNDEF]'
2018-08-24 21:03:53 us=984252 crl_file = '[UNDEF]'
2018-08-24 21:03:53 us=984263 ns_cert_type = 0
2018-08-24 21:03:53 us=984281 remote_cert_ku[i] = 65535
2018-08-24 21:03:53 us=984292 remote_cert_ku[i] = 0
2018-08-24 21:03:53 us=984303 remote_cert_ku[i] = 0
2018-08-24 21:03:53 us=984350 remote_cert_ku[i] = 0
2018-08-24 21:03:53 us=984387 remote_cert_ku[i] = 0
2018-08-24 21:03:53 us=984412 remote_cert_ku[i] = 0
2018-08-24 21:03:53 us=984437 remote_cert_ku[i] = 0
2018-08-24 21:03:53 us=984448 remote_cert_ku[i] = 0
2018-08-24 21:03:53 us=984459 remote_cert_ku[i] = 0
2018-08-24 21:03:53 us=984469 remote_cert_ku[i] = 0
2018-08-24 21:03:53 us=984479 remote_cert_ku[i] = 0
2018-08-24 21:03:53 us=984489 remote_cert_ku[i] = 0
2018-08-24 21:03:53 us=984500 remote_cert_ku[i] = 0
2018-08-24 21:03:53 us=984510 remote_cert_ku[i] = 0
2018-08-24 21:03:53 us=984521 remote_cert_ku[i] = 0
2018-08-24 21:03:53 us=984531 remote_cert_ku[i] = 0
2018-08-24 21:03:53 us=984542 remote_cert_eku = 'TLS Web Server Authentication'
2018-08-24 21:03:53 us=984553 ssl_flags = 0
2018-08-24 21:03:53 us=984563 tls_timeout = 2
2018-08-24 21:03:53 us=984574 renegotiate_bytes = -1
2018-08-24 21:03:53 us=984585 renegotiate_packets = 0
2018-08-24 21:03:53 us=984595 renegotiate_seconds = 3600
2018-08-24 21:03:53 us=984606 handshake_window = 60
2018-08-24 21:03:53 us=984616 transition_window = 3600
2018-08-24 21:03:53 us=984627 single_session = DISABLED
2018-08-24 21:03:53 us=984637 push_peer_info = DISABLED
2018-08-24 21:03:53 us=984647 tls_exit = DISABLED
2018-08-24 21:03:53 us=984658 tls_auth_file = '[[INLINE]]'
2018-08-24 21:03:53 us=984668 tls_crypt_file = '[UNDEF]'
2018-08-24 21:03:53 us=984679 pkcs11_protected_authentication = DISABLED
2018-08-24 21:03:53 us=984690 pkcs11_protected_authentication = DISABLED
2018-08-24 21:03:53 us=984700 pkcs11_protected_authentication = DISABLED
2018-08-24 21:03:53 us=984710 pkcs11_protected_authentication = DISABLED
2018-08-24 21:03:53 us=984721 pkcs11_protected_authentication = DISABLED
2018-08-24 21:03:53 us=984731 pkcs11_protected_authentication = DISABLED
2018-08-24 21:03:53 us=984742 pkcs11_protected_authentication = DISABLED
2018-08-24 21:03:53 us=984752 pkcs11_protected_authentication = DISABLED
2018-08-24 21:03:53 us=984762 pkcs11_protected_authentication = DISABLED
2018-08-24 21:03:53 us=984805 pkcs11_protected_authentication = DISABLED
2018-08-24 21:03:53 us=984816 pkcs11_protected_authentication = DISABLED
2018-08-24 21:03:53 us=984827 pkcs11_protected_authentication = DISABLED
2018-08-24 21:03:53 us=984838 pkcs11_protected_authentication = DISABLED
2018-08-24 21:03:53 us=984848 pkcs11_protected_authentication = DISABLED
2018-08-24 21:03:53 us=984858 pkcs11_protected_authentication = DISABLED
2018-08-24 21:03:53 us=984869 pkcs11_protected_authentication = DISABLED
2018-08-24 21:03:53 us=984879 pkcs11_private_mode = 00000000
2018-08-24 21:03:53 us=984890 pkcs11_private_mode = 00000000
2018-08-24 21:03:53 us=984900 pkcs11_private_mode = 00000000
2018-08-24 21:03:53 us=984911 pkcs11_private_mode = 00000000
2018-08-24 21:03:53 us=984922 pkcs11_private_mode = 00000000
2018-08-24 21:03:53 us=984934 pkcs11_private_mode = 00000000
2018-08-24 21:03:53 us=984950 pkcs11_private_mode = 00000000
2018-08-24 21:03:53 us=984973 pkcs11_private_mode = 00000000
2018-08-24 21:03:53 us=984992 pkcs11_private_mode = 00000000
2018-08-24 21:03:53 us=985005 pkcs11_private_mode = 00000000
2018-08-24 21:03:53 us=985027 pkcs11_private_mode = 00000000
2018-08-24 21:03:53 us=985039 pkcs11_private_mode = 00000000
2018-08-24 21:03:53 us=985071 pkcs11_private_mode = 00000000
2018-08-24 21:03:53 us=985137 pkcs11_private_mode = 00000000
2018-08-24 21:03:53 us=985169 pkcs11_private_mode = 00000000
2018-08-24 21:03:53 us=985204 pkcs11_private_mode = 00000000
2018-08-24 21:03:53 us=985217 pkcs11_cert_private = DISABLED
2018-08-24 21:03:53 us=985247 pkcs11_cert_private = DISABLED
2018-08-24 21:03:53 us=985269 pkcs11_cert_private = DISABLED
2018-08-24 21:03:53 us=985286 pkcs11_cert_private = DISABLED
2018-08-24 21:03:53 us=985311 pkcs11_cert_private = DISABLED
2018-08-24 21:03:53 us=985328 pkcs11_cert_private = DISABLED
2018-08-24 21:03:53 us=985344 pkcs11_cert_private = DISABLED
2018-08-24 21:03:53 us=985360 pkcs11_cert_private = DISABLED
2018-08-24 21:03:53 us=985387 pkcs11_cert_private = DISABLED
2018-08-24 21:03:53 us=985413 pkcs11_cert_private = DISABLED
2018-08-24 21:03:53 us=985430 pkcs11_cert_private = DISABLED
2018-08-24 21:03:53 us=985446 pkcs11_cert_private = DISABLED
2018-08-24 21:03:53 us=985462 pkcs11_cert_private = DISABLED
2018-08-24 21:03:53 us=985478 pkcs11_cert_private = DISABLED
2018-08-24 21:03:53 us=985494 pkcs11_cert_private = DISABLED
2018-08-24 21:03:53 us=985543 pkcs11_cert_private = DISABLED
2018-08-24 21:03:53 us=985560 pkcs11_pin_cache_period = -1
2018-08-24 21:03:53 us=985577 pkcs11_id = '[UNDEF]'
2018-08-24 21:03:53 us=985594 pkcs11_id_management = DISABLED
2018-08-24 21:03:53 us=985855 server_network = 0.0.0.0
2018-08-24 21:03:53 us=985874 server_netmask = 0.0.0.0
2018-08-24 21:03:53 us=985901 server_network_ipv6 = ::
2018-08-24 21:03:53 us=985914 server_netbits_ipv6 = 0
2018-08-24 21:03:53 us=985926 server_bridge_ip = 0.0.0.0
2018-08-24 21:03:53 us=985938 server_bridge_netmask = 0.0.0.0
2018-08-24 21:03:53 us=985950 server_bridge_pool_start = 0.0.0.0
2018-08-24 21:03:53 us=985961 server_bridge_pool_end = 0.0.0.0
2018-08-24 21:03:53 us=985987 ifconfig_pool_defined = DISABLED
2018-08-24 21:03:53 us=986016 ifconfig_pool_start = 0.0.0.0
2018-08-24 21:03:53 us=986037 ifconfig_pool_end = 0.0.0.0
2018-08-24 21:03:53 us=986057 ifconfig_pool_netmask = 0.0.0.0
2018-08-24 21:03:53 us=986075 ifconfig_pool_persist_filename = '[UNDEF]'
2018-08-24 21:03:53 us=986092 ifconfig_pool_persist_refresh_freq = 600
2018-08-24 21:03:53 us=986109 ifconfig_ipv6_pool_defined = DISABLED
2018-08-24 21:03:53 us=986128 ifconfig_ipv6_pool_base = ::
2018-08-24 21:03:53 us=986146 ifconfig_ipv6_pool_netbits = 0
2018-08-24 21:03:53 us=986196 n_bcast_buf = 256
2018-08-24 21:03:53 us=986214 tcp_queue_limit = 64
2018-08-24 21:03:53 us=986230 real_hash_size = 256
2018-08-24 21:03:53 us=986247 virtual_hash_size = 256
2018-08-24 21:03:53 us=986264 client_connect_script = '[UNDEF]'
2018-08-24 21:03:53 us=986280 learn_address_script = '[UNDEF]'
2018-08-24 21:03:53 us=986297 client_disconnect_script = '[UNDEF]'
2018-08-24 21:03:53 us=986314 client_config_dir = '[UNDEF]'
2018-08-24 21:03:53 us=986330 ccd_exclusive = DISABLED
2018-08-24 21:03:53 us=986347 tmp_dir = '/var/folders/z7/r_6mhwfj11q5mg3d50thw9dw0000gn/T/'
2018-08-24 21:03:53 us=986364 push_ifconfig_defined = DISABLED
2018-08-24 21:03:53 us=986382 push_ifconfig_local = 0.0.0.0
2018-08-24 21:03:53 us=986400 push_ifconfig_remote_netmask = 0.0.0.0
2018-08-24 21:03:53 us=986416 push_ifconfig_ipv6_defined = DISABLED
2018-08-24 21:03:53 us=986435 push_ifconfig_ipv6_local = ::/0
2018-08-24 21:03:53 us=986452 push_ifconfig_ipv6_remote = ::
2018-08-24 21:03:53 us=986468 enable_c2c = DISABLED
2018-08-24 21:03:53 us=986489 duplicate_cn = DISABLED
2018-08-24 21:03:53 us=986503 cf_max = 0
2018-08-24 21:03:53 us=986514 cf_per = 0
2018-08-24 21:03:53 us=986525 max_clients = 1024
2018-08-24 21:03:53 us=986535 max_routes_per_client = 256
2018-08-24 21:03:53 us=986546 auth_user_pass_verify_script = '[UNDEF]'
2018-08-24 21:03:53 us=986557 auth_user_pass_verify_script_via_file = DISABLED
2018-08-24 21:03:53 us=986567 auth_token_generate = DISABLED
2018-08-24 21:03:53 us=986577 auth_token_lifetime = 0
2018-08-24 21:03:53 us=986588 port_share_host = '[UNDEF]'
2018-08-24 21:03:53 us=986598 port_share_port = '[UNDEF]'
2018-08-24 21:03:53 us=986608 client = ENABLED
2018-08-24 21:03:53 us=986619 pull = ENABLED
2018-08-24 21:03:53 us=986629 auth_user_pass_file = '[UNDEF]'
2018-08-24 21:03:53 us=986645 OpenVPN 2.4.6 x86_64-apple-darwin [SSL (OpenSSL)] [LZO] [LZ4] [PKCS11] [MH/RECVDA] [AEAD] built on Jun 25 2018
2018-08-24 21:03:53 us=986727 library versions: OpenSSL 1.0.2o 27 Mar 2018, LZO 2.10
2018-08-24 21:03:53 us=989276 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:60499
2018-08-24 21:03:53 us=989755 Need hold release from management interface, waiting...
2018-08-24 21:03:53 *Tunnelblick: openvpnstart starting OpenVPN
2018-08-24 21:03:54 *Tunnelblick: openvpnstart log:
OpenVPN started successfully. Command used to start OpenVPN (one argument per displayed line):
/Applications/Tunnelblick.app/Contents/Resources/openvpn/openvpn-2.4.6-openssl-1.0.2o/openvpn
--daemon
--log
/Library/Application Support/Tunnelblick/Logs/-SLibrary-SApplication Support-STunnelblick-SShared-SNicknamelan.tblk-SContents-SResources-Sconfig.ovpn.1793_0_3_0_1065264.60499.openvpn.log
--cd
/Library/Application Support/Tunnelblick/Shared/Nicknamelan.tblk/Contents/Resources
--setenv
IV_GUI_VER
"net.tunnelblick.tunnelblick 5080 3.7.6a (build 5080)"
--verb
7
--config
/Library/Application Support/Tunnelblick/Shared/Nicknamelan.tblk/Contents/Resources/config.ovpn
--verb
7
--cd
/Library/Application Support/Tunnelblick/Shared/Nicknamelan.tblk/Contents/Resources
--management
127.0.0.1
60499
/Library/Application Support/Tunnelblick/bbpgcegiaikmcpdfgokkapbhdallpenkebbipnie.mip
--management-query-passwords
--management-hold
--script-security
2
--up
/Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw
--down
/Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw
2018-08-24 21:03:54 *Tunnelblick: Established communication with OpenVPN
2018-08-24 21:03:54 us=66800 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:60499
2018-08-24 21:03:54 us=99669 MANAGEMENT: CMD 'pid'
2018-08-24 21:03:54 us=100171 MANAGEMENT: CMD 'state on'
2018-08-24 21:03:54 us=100555 MANAGEMENT: CMD 'state'
2018-08-24 21:03:54 us=100838 MANAGEMENT: CMD 'bytecount 1'
2018-08-24 21:03:54 us=101816 MANAGEMENT: CMD 'hold release'
2018-08-24 21:03:54 us=103095 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2018-08-24 21:03:54 us=112616 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
2018-08-24 21:03:54 us=112916 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
2018-08-24 21:03:54 us=113124 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 28 bytes
2018-08-24 21:03:54 us=113331 LZO compression initializing
2018-08-24 21:03:54 us=114515 Control Channel MTU parms [ L:1622 D:1184 EF:66 EB:0 ET:0 EL:3 ]
2018-08-24 21:03:54 us=114892 Data Channel MTU parms [ L:1622 D:1450 EF:122 EB:406 ET:0 EL:3 ]
2018-08-24 21:03:54 us=115140 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 40 bytes
2018-08-24 21:03:54 us=115346 calc_options_string_link_mtu: link-mtu 1622 -> 1542
2018-08-24 21:03:54 us=115567 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 40 bytes
2018-08-24 21:03:54 us=115841 calc_options_string_link_mtu: link-mtu 1622 -> 1542
2018-08-24 21:03:54 us=116070 Local Options String (VER=V4): 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,keydir 1,cipher BF-CBC,auth SHA1,keysize 128,tls-auth,key-method 2,tls-client'
2018-08-24 21:03:54 us=116280 Expected Remote Options String (VER=V4): 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,keydir 0,cipher BF-CBC,auth SHA1,keysize 128,tls-auth,key-method 2,tls-server'
2018-08-24 21:03:54 us=116474 TCP/UDP: Preserving recently used remote address: [AF_INET]xx.xxx.xx.xx:1194
2018-08-24 21:03:54 us=116700 Socket Buffers: R=[196724->196724] S=[9216->9216]
2018-08-24 21:03:54 us=116891 UDP link local: (not bound)
2018-08-24 21:03:54 us=117078 UDP link remote: [AF_INET]xx.xxx.xx.xx:1194
2018-08-24 21:03:54 us=117313 MANAGEMENT: >STATE:1535169834,WAIT,,,,,,
2018-08-24 21:03:54 us=117673 UDP WRITE [42] to [AF_INET]xx.xxx.xx.xx:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #1 ] [ ] pid=0 DATA len=0
2018-08-24 21:03:56 us=270877 UDP WRITE [42] to [AF_INET]xx.xxx.xx.xx:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #2 ] [ ] pid=0 DATA len=0
2018-08-24 21:04:00 us=709239 UDP WRITE [42] to [AF_INET]xx.xxx.xx.xx:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #3 ] [ ] pid=0 DATA len=0
2018-08-24 21:04:08 us=965567 UDP WRITE [42] to [AF_INET]xx.xxx.xx.xx:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #4 ] [ ] pid=0 DATA len=0
2018-08-24 21:04:24 us=198292 UDP WRITE [42] to [AF_INET]xx.xxx.xx.xx:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #5 ] [ ] pid=0 DATA len=0
2018-08-24 21:04:54 us=164434 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2018-08-24 21:04:54 us=164998 TLS Error: TLS handshake failed
2018-08-24 21:04:54 us=169924 TCP/UDP: Closing socket
2018-08-24 21:04:54 us=175990 SIGUSR1[soft,tls-error] received, process restarting
2018-08-24 21:04:54 us=176312 MANAGEMENT: >STATE:1535169894,RECONNECTING,tls-error,,,,,
2018-08-24 21:04:54 us=188833 MANAGEMENT: CMD 'hold release'
2018-08-24 21:04:54 us=189207 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2018-08-24 21:04:54 us=190865 Re-using SSL/TLS context
2018-08-24 21:04:54 us=192157 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 28 bytes
2018-08-24 21:04:54 us=193526 LZO compression initializing
2018-08-24 21:04:54 us=194855 Control Channel MTU parms [ L:1622 D:1184 EF:66 EB:0 ET:0 EL:3 ]
2018-08-24 21:04:54 us=196396 Data Channel MTU parms [ L:1622 D:1450 EF:122 EB:406 ET:0 EL:3 ]
2018-08-24 21:04:54 us=198907 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 40 bytes
2018-08-24 21:04:54 us=199185 calc_options_string_link_mtu: link-mtu 1622 -> 1542
2018-08-24 21:04:54 us=199421 crypto_adjust_frame_parameters: Adjusting frame parameters for crypto by 40 bytes
2018-08-24 21:04:54 us=199652 calc_options_string_link_mtu: link-mtu 1622 -> 1542
2018-08-24 21:04:54 us=199904 Local Options String (VER=V4): 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,keydir 1,cipher BF-CBC,auth SHA1,keysize 128,tls-auth,key-method 2,tls-client'
2018-08-24 21:04:54 us=200097 Expected Remote Options String (VER=V4): 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,keydir 0,cipher BF-CBC,auth SHA1,keysize 128,tls-auth,key-method 2,tls-server'
2018-08-24 21:04:54 us=200313 TCP/UDP: Preserving recently used remote address: [AF_INET]xx.xxx.xx.xx:1194
2018-08-24 21:04:54 us=200542 Socket Buffers: R=[196724->196724] S=[9216->9216]
2018-08-24 21:04:54 us=200737 UDP link local: (not bound)
2018-08-24 21:04:54 us=200968 UDP link remote: [AF_INET]xx.xxx.xx.xx:1194
2018-08-24 21:04:54 us=201325 MANAGEMENT: >STATE:1535169894,WAIT,,,,,,
2018-08-24 21:04:54 us=201612 UDP WRITE [42] to [AF_INET]xx.xxx.xx.xx:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #1 ] [ ] pid=0 DATA len=0
2018-08-24 21:04:54 us=202040 MANAGEMENT: CMD 'hold release'
2018-08-24 21:04:56 us=478409 UDP WRITE [42] to [AF_INET]xx.xxx.xx.xx:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #2 ] [ ] pid=0 DATA len=0
2018-08-24 21:05:01 us=39132 UDP WRITE [42] to [AF_INET]xx.xxx.xx.xx:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #3 ] [ ] pid=0 DATA len=0
2018-08-24 21:05:09 us=263669 UDP WRITE [42] to [AF_INET]xx.xxx.xx.xx:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #4 ] [ ] pid=0 DATA len=0
2018-08-24 21:05:17 *Tunnelblick: Disconnecting; VPN Details… window disconnect button pressed
2018-08-24 21:05:17 *Tunnelblick: No 'pre-disconnect.sh' script to execute
2018-08-24 21:05:17 *Tunnelblick: Disconnecting using 'kill'
2018-08-24 21:05:17 us=475289 event_wait : Interrupted system call (code=4)
2018-08-24 21:05:17 us=481222 TCP/UDP: Closing socket
2018-08-24 21:05:17 us=482134 SIGTERM[hard,] received, process exiting
2018-08-24 21:05:17 us=482454 MANAGEMENT: >STATE:1535169917,EXITING,SIGTERM,,,,,
2018-08-24 21:05:17 us=483990 PKCS#11: Terminating openssl
2018-08-24 21:05:17 us=484267 PKCS#11: Removing providers
2018-08-24 21:05:17 us=484482 PKCS#11: Releasing sessions
2018-08-24 21:05:17 us=484686 PKCS#11: Marking as uninitialized
2018-08-24 21:05:18 *Tunnelblick: No 'post-disconnect.sh' script to execute
2018-08-24 21:05:18 *Tunnelblick: Expected disconnection occurred.
================================================================================
"Sanitized" full configuration file
client
dev tun
proto udp
fast-io
remote xx.xxx.xx.xx 1194
remote-cert-tls server
nobind
persist-key
persist-tun
compress lzo
verb 3
key-direction 1
pull-filter ignore "block-outside-dns"
<ca>
[Security-related line(s) omitted]
</ca>
<cert>
[Security-related line(s) omitted]
</cert>
<key>
[Security-related line(s) omitted]
</key>
<tls-auth>
[Security-related line(s) omitted]
</tls-auth>