<div dir="ltr"><div>Hi!<br><br>As OpenVPN seems to become banned in increasing number of 
countries, I had to look for a way to foil DPI. Wrapping OpenVPN traffic
 into stunnel SSL-secured connection seems promising but... On Windows 
machine it really works just fine. But on macOS it connects, but then no
 surfing or other Internet application works whatsoever. Looks like DNS 
problem but may be it's different... <br><br>Moreover, in 40 secs or so 
Tunnelblick disconnects with message "2017-11-10 00:08:54 *Tunnelblick: 
After 30.0 seconds, gave up trying to fetch IP address information using
 the ipInfo host's name after connecting.<br>2017-11-10 00:09:30 
*Tunnelblick: After 30.0 seconds, gave up trying to fetch IP address 
information using the ipInfo host's IP address after connecting". Then 
it tries to connect again but never succeeds and cycles forever.<br><br>Please find stunnel config and Tunnelblik full log below. Would appreciate any help!<br><br></div>[STUNNEL]<br><div><br>$ stunnel -version<br>stunnel 5.23 on x86_64-apple-darwin14.5.0 platform<br>Compiled with OpenSSL 0.9.8zd 8 Jan 2015<br>Running  with OpenSSL 0.9.8zh 14 Jan 2016<br>Update OpenSSL shared libraries or rebuild stunnel<br>Threading:PTHREAD Sockets:POLL,IPv6 TLS:ENGINE,OCSP<br> <br>Global options:<br>debug                  = daemon.notice<br>RNDbytes               = 64<br>RNDfile                = /dev/urandom<br>RNDoverwrite           = yes<br> <br>Service-level options:<br>ciphers                = HIGH:+3DES:+DH:!aNULL:!SSLv2<br>curve                  = prime256v1<br>debug                  = notice<br>logId                  = sequential<br>options                = NO_SSLv2<br>options                = NO_SSLv3<br>sessionCacheSize       = 1000<br>sessionCacheTimeout    = 300 seconds<br>stack                  = 65536 bytes<br>TIMEOUTbusy            = 300 seconds<br>TIMEOUTclose           = 60 seconds<br>TIMEOUTconnect         = 10 seconds<br>TIMEOUTidle            = 43200 seconds<br>verify                 = none<br><br>stunnel.conf file:<br><br>cert=stunnel.pem<br>options=NO_SSLv2<br><br>[openvpn]<br>client=yes<br>accept=localhost:989<br>connect=X.X.X.X:990<br><br><br><br></div><div>[TUNNELBLICK]<br><br></div><div>*Tunnelblick: OS X 10.12.6; Tunnelblick 3.7.4 (build 4900); prior version 3.7.3 (build 4880); Standard user<br>git commit 0f68fae3cabe6b2ebdc9fbb3054232074c03bbfb<br><br><br>Configuration client2_pc_stunnel<br><br>"Sanitized" condensed configuration file for /Library/Application Support/Tunnelblick/Shared/client2_pc_stunnel.tblk:<br><br>client<br>dev tun<br>proto tcp<br>remote 127.0.0.1 989<br>resolv-retry infinite<br>nobind<br>persist-key<br>persist-tun<br>verb 3<br>remote-cert-tls server<br>keepalive 10 120<br>tls-client<br>key-direction 1<br><ca><br>[Security-related line(s) omitted]<br></ca><br><cert><br>[Security-related line(s) omitted]<br></cert><br><key><br>[Security-related line(s) omitted]<br></key><br><tls-auth><br>[Security-related line(s) omitted]<br></tls-auth><br><br><br>================================================================================<br><br>XXX<br><br>================================================================================<br><br>There are no unusual files in client2_pc_stunnel.tblk<br><br>================================================================================<br><br>Configuration preferences:<br><br>useDNS = 1<br>-notMonitoringConnection = 0<br>-resetPrimaryInterfaceAfterDisconnect = 1<br>-routeAllTrafficThroughVpn = 1<br>-runMtuTest = 0<br>-doNotFlushCache = 0<br>-useRouteUpInsteadOfUp = 1<br>-openvpnVersion = -<br>-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0<br>-keepConnected = 1<br>-lastConnectionSucceeded = 1<br>-prependDomainNameToSearchDomains = 1<br><br>================================================================================<br><br>Wildcard preferences:<br><br>-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0<br><br>================================================================================<br><br>Program preferences:<br><br>skipWarningAboutNonAdminUpdatingTunnelblick = 1<br>skipWarningThatIPANotFetchedBeforeConnection = 1<br>skipWarningThatInternetIsNotReachable = 1<br>skipWarningAboutPlacingIconNearTheSpotlightIcon = 1<br>placeIconInStandardPositionInStatusBar = 0<br>launchAtNextLogin = 1<br>notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0<br>tunnelblickVersionHistory = (<br>    "3.7.4 (build 4900)",<br>    "3.7.3 (build 4880)",<br>    "3.7.2a (build 4851)",<br>    "3.7.2 (build 4850)",<br>    "3.7.1b (build 4813)",<br>    "3.7.1a (build 4812)",<br>    "3.7.1 (build 4811)",<br>    "3.7.0 (build 4790)",<br>    "3.6.9 (build 4685)",<br>    "3.6.8 (build 4625)"<br>)<br>statusDisplayNumber = 0<br>lastLaunchTime = 531944638.592689<br>showConnectedDurations = 1<br>lastLanguageAtLaunchWasRTL = 0<br>connectionWindowDisplayCriteria = showWhenConnecting<br>maxLogDisplaySize = 102400<br>lastConnectedDisplayName = client2_pc_stunnel<br>keyboardShortcutIndex = 1<br>updateCheckAutomatically = 1<br>NSWindow Frame SettingsSheetWindow = 367 167 829 524 0 0 1280 777 <br>NSWindow Frame ConnectingWindow = 469 442 389 187 0 0 1280 777 <br>NSWindow Frame SUStatusFrame = 624 664 400 129 0 0 1600 877 <br>NSWindow Frame SUUpdateAlert = 516 363 620 392 0 0 1600 877 <br>NSWindow Frame ListingWindow = 64 330 500 422 0 0 1280 777 <br>detailsWindowFrameVersion = 4900<br>detailsWindowFrame = {{48, 0}, {1232, 777}}<br>detailsWindowLeftFrame = {{0, 0}, {224, 659}}<br>detailsWindowViewIndex = 0<br>detailsWindowConfigurationsTabIdentifier = log<br>leftNavSelectedDisplayName = client2_pc_stunnel<br>AdvancedWindowTabIdentifier = whileConnected<br>haveDealtWithOldTunTapPreferences = 1<br>haveDealtWithOldLoginItem = 1<br>SUEnableAutomaticChecks = 1<br>SUFeedURL = <a href="https://www.tunnelblick.net/appcast-s.rss" rel="nofollow">https://www.tunnelblick.net/appcast-s.rss</a><br>SUScheduledCheckInterval = 86400<br>SUSendProfileInfo = 1<br>SULastCheckTime = 2017-11-09 18:24:28 +0000<br>SULastProfileSubmissionDate = 2017-11-08 18:10:57 +0000<br>SUHasLaunchedBefore = 1<br>WebKitDefaultFontSize = 11<br>WebKitStandardFont = .AppleSystemUIFont<br>askedUserIfOKToCheckThatIPAddressDidNotChangeAfterConnection = 1<br>haveDealtWithSparkle1dot5b6 = 1<br>tunnelblickdHash = 004cdba8e08abd144bc48409040bc80e29c12ee9741ed7d73754f51d2547f7ea<br>tunnelblickdPlistHash = ce400d395d1801b003398461b5420021f4d591822783a04b79b2f43956d28620<br>updateSendProfileInfo = 1<br><br>================================================================================<br><br>Tunnelblick Log:<br><br>*Tunnelblick: OS X 10.12.6; Tunnelblick 3.7.4 (build 4900); prior version 3.7.3 (build 4880)<br>2017-11-10 00:08:03 *Tunnelblick: Attempting connection with client2_pc_stunnel; Set nameserver = 769; monitoring connection<br>2017-11-10
 00:08:03 *Tunnelblick: openvpnstart start client2_pc_stunnel.tblk 1337 
769 0 3 0 1099696 -ptADGNWradsgnw 2.4.4-libressl-2.5.5<br>2017-11-10 00:08:03 *Tunnelblick: openvpnstart log:<br>     OpenVPN started successfully. Command used to start OpenVPN (one argument per displayed line):<br>     <br>          /Applications/Tunnelblick.app/Contents/Resources/openvpn/openvpn-2.4.4-libressl-2.5.5/openvpn<br>          --daemon<br>          --log<br>         
 /Library/Application Support/Tunnelblick/Logs/-SLibrary-SApplication 
Support-STunnelblick-SShared-Sclient2_pc_stunnel.tblk-SContents-SResources-Sconfig.ovpn.769_0_3_0_1099696.1337.openvpn.log<br>          --cd<br>          /Library/Application Support/Tunnelblick/Shared/client2_pc_stunnel.tblk/Contents/Resources<br>          --setenv<br>          IV_GUI_VER<br>          "net.tunnelblick.tunnelblick 4900 3.7.4 (build 4900)"<br>          --verb<br>          3<br>          --config<br>          /Library/Application Support/Tunnelblick/Shared/client2_pc_stunnel.tblk/Contents/Resources/config.ovpn<br>          --verb<br>          3<br>          --cd<br>          /Library/Application Support/Tunnelblick/Shared/client2_pc_stunnel.tblk/Contents/Resources<br>          --management<br>          127.0.0.1<br>          1337<br>          --management-query-passwords<br>          --management-hold<br>          --redirect-gateway<br>          def1<br>          --script-security<br>          2<br>          --route-up<br>          /Applications/Tunnelblick.app/Contents/Resources/<a href="http://client.up.tunnelblick.sh" rel="nofollow">client.up.tunnelblick.sh</a> -9 -d -f -m -p -r -w -ptADGNWradsgnw<br>          --down<br>          /Applications/Tunnelblick.app/Contents/Resources/<a href="http://client.down.tunnelblick.sh" rel="nofollow">client.down.tunnelblick.sh</a> -9 -d -f -m -p -r -w -ptADGNWradsgnw<br><br>2017-11-10
 00:08:03 OpenVPN 2.4.4 x86_64-apple-darwin [SSL (OpenSSL)] [LZO] [LZ4] 
[PKCS11] [MH/RECVDA] [AEAD] built on Nov  2 2017<br>2017-11-10 00:08:03 library versions: LibreSSL 2.5.5, LZO 2.10<br>2017-11-10 00:08:03 MANAGEMENT: TCP Socket listening on [AF_INET]<a href="http://127.0.0.1:1337" rel="nofollow">127.0.0.1:1337</a><br>2017-11-10 00:08:03 Need hold release from management interface, waiting...<br>2017-11-10 00:08:03 MANAGEMENT: Client connected from [AF_INET]<a href="http://127.0.0.1:1337" rel="nofollow">127.0.0.1:1337</a><br>2017-11-10 00:08:03 *Tunnelblick: openvpnstart starting OpenVPN<br>2017-11-10 00:08:04 *Tunnelblick: Established communication with OpenVPN<br>2017-11-10 00:08:04 MANAGEMENT: CMD 'pid'<br>2017-11-10 00:08:04 MANAGEMENT: CMD 'state on'<br>2017-11-10 00:08:04 MANAGEMENT: CMD 'state'<br>2017-11-10 00:08:04 MANAGEMENT: CMD 'bytecount 1'<br>2017-11-10 00:08:04 MANAGEMENT: CMD 'hold release'<br>2017-11-10 00:08:04 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts<br>2017-11-10 00:08:04 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication<br>2017-11-10 00:08:04 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication<br>2017-11-10 00:08:04 TCP/UDP: Preserving recently used remote address: [AF_INET]<a href="http://127.0.0.1:989" rel="nofollow">127.0.0.1:989</a><br>2017-11-10 00:08:04 Socket Buffers: R=[131072->131072] S=[131072->131072]<br>2017-11-10 00:08:04 Attempting to establish TCP connection with [AF_INET]<a href="http://127.0.0.1:989" rel="nofollow">127.0.0.1:989</a> [nonblock]<br>2017-11-10 00:08:04 MANAGEMENT: >STATE:1510254484,TCP_CONNECT,,,,,,<br>2017-11-10 00:08:04 TCP connection established with [AF_INET]<a href="http://127.0.0.1:989" rel="nofollow">127.0.0.1:989</a><br>2017-11-10 00:08:04 TCP_CLIENT link local: (not bound)<br>2017-11-10 00:08:04 TCP_CLIENT link remote: [AF_INET]<a href="http://127.0.0.1:989" rel="nofollow">127.0.0.1:989</a><br>2017-11-10 00:08:04 MANAGEMENT: >STATE:1510254484,WAIT,,,,,,<br>2017-11-10 00:08:07 MANAGEMENT: >STATE:1510254487,AUTH,,,,,,<br>2017-11-10 00:08:07 TLS: Initial packet from [AF_INET]<a href="http://127.0.0.1:989" rel="nofollow">127.0.0.1:989</a>, sid=db4e0f35 f615606b<br>2017-11-10 00:08:07 VERIFY OK: depth=1, C=UZ, ST=UZ, L=XXX, O=XXX, OU=VPNUnit, CN=<a href="http://talk.ingichkimetals.com" rel="nofollow">XXX</a>, name=EasyRSA, emailAddress=XXX<a rel="nofollow"></a><br>2017-11-10 00:08:07 VERIFY KU OK<br>2017-11-10 00:08:07 Validating certificate extended key usage<br>2017-11-10 00:08:07 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication<br>2017-11-10 00:08:07 VERIFY EKU OK<br>2017-11-10 00:08:07 VERIFY OK: depth=0, C=UZ, ST=UZ, L=XXX, O=IngMet, OU=VPNUnit, CN=server, name=EasyRSA, emailAddress=<a rel="nofollow">XXX</a><br>2017-11-10 00:08:08 Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 2048 bit RSA<br>2017-11-10 00:08:08 [server] Peer Connection Initiated with [AF_INET]<a href="http://127.0.0.1:989" rel="nofollow">127.0.0.1:989</a><br>2017-11-10 00:08:09 MANAGEMENT: >STATE:1510254489,GET_CONFIG,,,,,,<br>2017-11-10 00:08:09 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)<br>2017-11-10
 00:08:10 PUSH: Received control message: 'PUSH_REPLY,redirect-gateway 
local def1,route 10.0.26.0 255.255.255.0,dhcp-option DNS 10.0.26.1,route
 10.0.26.1,topology net30,ping 10,ping-restart 120,ifconfig 10.0.26.10 
10.0.26.9,peer-id 0,cipher AES-256-GCM'<br>2017-11-10 00:08:10 OPTIONS IMPORT: timers and/or timeouts modified<br>2017-11-10 00:08:10 OPTIONS IMPORT: --ifconfig/up options modified<br>2017-11-10 00:08:10 OPTIONS IMPORT: route options modified<br>2017-11-10 00:08:10 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified<br>2017-11-10 00:08:10 OPTIONS IMPORT: peer-id set<br>2017-11-10 00:08:10 OPTIONS IMPORT: adjusting link_mtu to 1626<br>2017-11-10 00:08:10 OPTIONS IMPORT: data channel crypto options modified<br>2017-11-10 00:08:10 Data Channel: using negotiated cipher 'AES-256-GCM'<br>2017-11-10 00:08:10 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key<br>2017-11-10 00:08:10 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key<br>2017-11-10 00:08:10 Opening utun (connect(AF_SYS_CONTROL)): Resource busy (errno=16)<br>2017-11-10 00:08:10 Opened utun device utun1<br>2017-11-10 00:08:10 do_ifconfig, tt->did_ifconfig_ipv6_setup=0<br>2017-11-10 00:08:10 MANAGEMENT: >STATE:1510254490,ASSIGN_IP,,10.0.26.10,,,,<br>2017-11-10 00:08:10 /sbin/ifconfig utun1 delete<br>                                        ifconfig: ioctl (SIOCDIFADDR): Can't assign requested address<br>2017-11-10 00:08:10 NOTE: Tried to delete pre-existing tun/tap instance -- No Problem if failure<br>2017-11-10 00:08:10 /sbin/ifconfig utun1 10.0.26.10 10.0.26.9 mtu 1500 netmask 255.255.255.255 up<br>2017-11-10 00:08:10 /sbin/route add -net 0.0.0.0 10.0.26.9 128.0.0.0<br>                                        add net <a href="http://0.0.0.0" rel="nofollow">0.0.0.0</a>: gateway 10.0.26.9<br>2017-11-10 00:08:10 /sbin/route add -net 128.0.0.0 10.0.26.9 128.0.0.0<br>                                        add net <a href="http://128.0.0.0" rel="nofollow">128.0.0.0</a>: gateway 10.0.26.9<br>2017-11-10 00:08:10 MANAGEMENT: >STATE:1510254490,ADD_ROUTES,,,,,,<br>2017-11-10 00:08:10 /sbin/route add -net 10.0.26.0 10.0.26.9 255.255.255.0<br>                                        add net <a href="http://10.0.26.0" rel="nofollow">10.0.26.0</a>: gateway 10.0.26.9<br>2017-11-10 00:08:10 /sbin/route add -net 10.0.26.1 10.0.26.9 255.255.255.255<br>                                        add net <a href="http://10.0.26.1" rel="nofollow">10.0.26.1</a>: gateway 10.0.26.9<br>                                        **********************************************<br>                                        Start of output from <a href="http://client.up.tunnelblick.sh" rel="nofollow">client.up.tunnelblick.sh</a><br>                                       
 Retrieved from OpenVPN: name server(s) [ 10.0.26.1 ], search domain(s) 
[  ] and SMB server(s) [  ] and using default domain name [ openvpn ]<br>                                        Not aggregating ServerAddresses because running on OS X 10.6 or higher<br>                                       
 Prepending 'openvpn' to search domains '' because the search domains 
were not set manually (or are allowed to be changed) and 'Prepend domain
 name to search domains' was selected<br>                                        Saved the DNS and SMB configurations so they can be restored<br>                                        Changed DNS ServerAddresses setting from '172.20.10.1' to '10.0.26.1'<br>                                        Changed DNS SearchDomains setting from '' to 'openvpn'<br>                                        Changed DNS DomainName setting from '' to 'openvpn'<br>                                        Did not change SMB NetBIOSName setting of ''<br>                                        Did not change SMB Workgroup setting of ''<br>                                        Did not change SMB WINSAddresses setting of ''<br>                                        DNS servers '10.0.26.1' will be used for DNS queries when the VPN is active<br>                                       
 NOTE: The DNS servers do not include any free public DNS servers known 
to Tunnelblick. This may cause DNS queries to fail or be intercepted or 
falsified even if they are directed through the VPN. Specify only known 
public DNS servers or DNS servers located on the VPN network to avoid 
such problems.<br>                                        Flushed the DNS cache via dscacheutil<br>                                        /usr/sbin/discoveryutil not present. Not flushing the DNS cache via discoveryutil<br>                                        Notified mDNSResponder that the DNS cache was flushed<br>                                        Setting up to monitor system configuration with process-network-changes<br>                                        End of output from <a href="http://client.up.tunnelblick.sh" rel="nofollow">client.up.tunnelblick.sh</a><br>                                        **********************************************<br>2017-11-10 00:08:13 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this<br>2017-11-10 00:08:13 Initialization Sequence Completed<br>2017-11-10 00:08:13 MANAGEMENT: >STATE:1510254493,CONNECTED,SUCCESS,10.0.26.10,127.0.0.1,989,127.0.0.1,50665<br>2017-11-10 00:08:14 *Tunnelblick: No 'connected.sh' script to execute<br>2017-11-10
 00:08:54 *Tunnelblick: After 30.0 seconds, gave up trying to fetch IP 
address information using the ipInfo host's name after connecting.<br>2017-11-10
 00:09:30 *Tunnelblick: After 30.0 seconds, gave up trying to fetch IP 
address information using the ipInfo host's IP address after connecting.<br>2017-11-10 00:10:13 [server] Inactivity timeout (--ping-restart), restarting<br>2017-11-10 00:10:13 SIGUSR1[soft,ping-restart] received, process restarting<br>2017-11-10 00:10:13 MANAGEMENT: >STATE:1510254613,RECONNECTING,ping-restart,,,,,<br>2017-11-10 00:10:14 *Tunnelblick: No 'reconnecting.sh' script to execute<br>2017-11-10 00:10:14 MANAGEMENT: CMD 'hold release'<br>2017-11-10 00:10:14 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts<br>2017-11-10 00:10:14 TCP/UDP: Preserving recently used remote address: [AF_INET]<a href="http://127.0.0.1:989" rel="nofollow">127.0.0.1:989</a><br>2017-11-10 00:10:14 Socket Buffers: R=[131072->131072] S=[131072->131072]<br>2017-11-10 00:10:14 Attempting to establish TCP connection with [AF_INET]<a href="http://127.0.0.1:989" rel="nofollow">127.0.0.1:989</a> [nonblock]<br>2017-11-10 00:10:14 MANAGEMENT: >STATE:1510254614,TCP_CONNECT,,,,,,<br>2017-11-10 00:10:15 TCP connection established with [AF_INET]<a href="http://127.0.0.1:989" rel="nofollow">127.0.0.1:989</a><br>2017-11-10 00:10:15 TCP_CLIENT link local: (not bound)<br>2017-11-10 00:10:15 TCP_CLIENT link remote: [AF_INET]<a href="http://127.0.0.1:989" rel="nofollow">127.0.0.1:989</a><br>2017-11-10 00:10:15 MANAGEMENT: >STATE:1510254615,WAIT,,,,,,<br>2017-11-10 00:10:24 Connection reset, restarting [-1]<br>2017-11-10 00:10:24 SIGUSR1[soft,connection-reset] received, process restarting<br>2017-11-10 00:10:24 MANAGEMENT: >STATE:1510254624,RECONNECTING,connection-reset,,,,,<br>2017-11-10 00:10:24 *Tunnelblick: No 'reconnecting.sh' script to execute<br>2017-11-10 00:10:24 MANAGEMENT: CMD 'hold release'<br>2017-11-10 00:10:24 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts<br>2017-11-10 00:10:24 TCP/UDP: Preserving recently used remote address: [AF_INET]<a href="http://127.0.0.1:989" rel="nofollow">127.0.0.1:989</a><br>2017-11-10 00:10:24 Socket Buffers: R=[131072->131072] S=[131072->131072]<br>2017-11-10 00:10:24 Attempting to establish TCP connection with [AF_INET]<a href="http://127.0.0.1:989" rel="nofollow">127.0.0.1:989</a> [nonblock]<br>2017-11-10 00:10:24 MANAGEMENT: >STATE:1510254624,TCP_CONNECT,,,,,,<br>2017-11-10 00:10:25 TCP connection established with [AF_INET]<a href="http://127.0.0.1:989" rel="nofollow">127.0.0.1:989</a><br>2017-11-10 00:10:25 TCP_CLIENT link local: (not bound)<br>2017-11-10 00:10:25 TCP_CLIENT link remote: [AF_INET]<a href="http://127.0.0.1:989" rel="nofollow">127.0.0.1:989</a><br>2017-11-10 00:10:25 MANAGEMENT: >STATE:1510254625,WAIT,,,,,,<br>2017-11-10 00:10:32 *Tunnelblick: Disconnecting; notification window disconnect button pressed<br>2017-11-10 00:10:33 *Tunnelblick: No 'pre-disconnect.sh' script to execute<br>2017-11-10 00:10:33 *Tunnelblick: Disconnecting using 'kill'<br>2017-11-10 00:10:33 event_wait : Interrupted system call (code=4)<br>2017-11-10 00:10:33 /sbin/route delete -net 10.0.26.0 10.0.26.9 255.255.255.0<br>                                        delete net <a href="http://10.0.26.0" rel="nofollow">10.0.26.0</a>: gateway 10.0.26.9<br>2017-11-10 00:10:33 /sbin/route delete -net 10.0.26.1 10.0.26.9 255.255.255.255<br>                                        delete net <a href="http://10.0.26.1" rel="nofollow">10.0.26.1</a>: gateway 10.0.26.9<br>2017-11-10 00:10:33 /sbin/route delete -net 0.0.0.0 10.0.26.9 128.0.0.0<br>                                        delete net <a href="http://0.0.0.0" rel="nofollow">0.0.0.0</a>: gateway 10.0.26.9<br>2017-11-10 00:10:33 /sbin/route delete -net 128.0.0.0 10.0.26.9 128.0.0.0<br>                                        delete net <a href="http://128.0.0.0" rel="nofollow">128.0.0.0</a>: gateway 10.0.26.9<br>2017-11-10 00:10:33 Closing TUN/TAP interface<br>2017-11-10 00:10:33 /Applications/Tunnelblick.app/Contents/Resources/<a href="http://client.down.tunnelblick.sh" rel="nofollow">client.down.tunnelblick.sh</a> -9 -d -f -m -p -r -w -ptADGNWradsgnw utun1 1500 1623 10.0.26.10 10.0.26.9 init<br>                                        **********************************************<br>                                        Start of output from <a href="http://client.down.tunnelblick.sh" rel="nofollow">client.down.tunnelblick.sh</a><br>                                        Cancelled monitoring of system configuration changes<br>                                        Restored the DNS and SMB configurations<br>                                        Flushed the DNS cache via dscacheutil<br>                                        /usr/sbin/discoveryutil not present. Not flushing the DNS cache via discoveryutil<br>                                        Notified mDNSResponder that the DNS cache was flushed<br>                                        Resetting primary interface 'en0' via networksetup -setairportpower en0 off/on...<br>                                        End of output from <a href="http://client.down.tunnelblick.sh" rel="nofollow">client.down.tunnelblick.sh</a><br>                                        **********************************************<br>2017-11-10 00:10:36 SIGTERM[hard,] received, process exiting<br>2017-11-10 00:10:36 MANAGEMENT: >STATE:1510254636,EXITING,SIGTERM,,,,,<br>2017-11-10 00:10:36 *Tunnelblick: No 'post-disconnect.sh' script to execute<br>2017-11-10 00:10:36 *Tunnelblick: Expected disconnection occurred.<br><br>================================================================================<br><br>"Sanitized" full configuration file<br><br>client<br>dev tun<br>proto tcp<br>remote 127.0.0.1 989<br>resolv-retry infinite<br>nobind<br>persist-key<br>persist-tun<br>verb 3<br>remote-cert-tls server<br>keepalive 10 120<br>tls-client<br>key-direction 1<br><br><br><ca><br> [Security-related line(s) omitted]<br></ca><br><br><cert><br> [Security-related line(s) omitted]<br></cert><br><br><key><br> [Security-related line(s) omitted]<br></key><br><br><tls-auth><br> [Security-related line(s) omitted]<br></tls-auth><br><br><br><br>================================================================================<br><br>ifconfig output:<br><br>lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384<br>    options=1203<RXCSUM,TXCSUM,TXSTATUS,SW_TIMESTAMP><br>    inet 127.0.0.1 netmask 0xff000000 <br>    inet6 ::1 prefixlen 128 <br>    inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1 <br>    nd6 options=201<PERFORMNUD,DAD><br>gif0: flags=8010<POINTOPOINT,MULTICAST> mtu 1280<br>stf0: flags=0<> mtu 1280<br>en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500<br>    ether 60:03:08:a6:ca:5a <br>    inet 172.20.10.2 netmask 0xfffffff0 broadcast 172.20.10.15<br>    media: autoselect<br>    status: active<br>en1: flags=963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX> mtu 1500<br>    options=60<TSO4,TSO6><br>    ether 72:00:01:d9:43:00 <br>    media: autoselect <full-duplex><br>    status: inactive<br>en2: flags=963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX> mtu 1500<br>    options=60<TSO4,TSO6><br>    ether 72:00:01:d9:43:01 <br>    media: autoselect <full-duplex><br>    status: inactive<br>p2p0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 2304<br>    ether 02:03:08:a6:ca:5a <br>    media: autoselect<br>    status: inactive<br>awdl0: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1484<br>    ether c2:f1:c7:85:b6:9d <br>    inet6 fe80::c0f1:c7ff:fe85:b69d%awdl0 prefixlen 64 scopeid 0x8 <br>    nd6 options=201<PERFORMNUD,DAD><br>    media: autoselect<br>    status: active<br>bridge0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500<br>    options=63<RXCSUM,TXCSUM,TSO4,TSO6><br>    ether 72:00:01:d9:43:00 <br>    Configuration:<br>        id 0:0:0:0:0:0 priority 0 hellotime 0 fwddelay 0<br>        maxage 0 holdcnt 0 proto stp maxaddr 100 timeout 1200<br>        root id 0:0:0:0:0:0 priority 0 ifcost 0 port 0<br>        ipfilter disabled flags 0x2<br>    member: en1 flags=3<LEARNING,DISCOVER><br>            ifmaxaddr 0 port 5 priority 0 path cost 0<br>    member: en2 flags=3<LEARNING,DISCOVER><br>            ifmaxaddr 0 port 6 priority 0 path cost 0<br>    media: <unknown type><br>    status: inactive<br>utun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 2000<br>    inet6 fe80::6c50:d369:e570:bf02%utun0 prefixlen 64 scopeid 0xa <br>    nd6 options=201<PERFORMNUD,DAD><br><br>================================================================================<br><br>Console Log:<br><br>2017-11-09 23:23:57 Tunnelblick[1595] Tunnelblick: OS X 10.12.6; Tunnelblick 3.7.4 (build 4900)<br>2017-11-09 23:23:57 Tunnelblick[1595] Warning: preferences contain unknown preference 'PMPrintingExpandedStateForPrint2'<br>2017-11-09 23:23:57 Tunnelblick[1595] Warning: preferences contain unknown preference 'userAgreementVersionAgreedTo'<br>2017-11-10
 00:08:54 Tunnelblick[1595] currentIPInfo(Name): IP address info could 
not be fetched within 35.4 seconds; the error was 'Error 
Domain=NSURLErrorDomain Code=-1001 "The request timed out." 
UserInfo={NSUnderlyingError=0x60800024a200 {Error 
Domain=kCFErrorDomainCFNetwork Code=-1001 "The request timed out." 
UserInfo={NSErrorFailingURLStringKey=<a href="https://tunnelblick.net/ipinfo" rel="nofollow">https://tunnelblick.net/ipinfo</a>, NSErrorFailingURLKey=<a href="https://tunnelblick.net/ipinfo" rel="nofollow">https://tunnelblick.net/ipinfo</a>,
 _kCFStreamErrorCodeKey=-2102, _kCFStreamErrorDomainKey=4, 
NSLocalizedDescription=The request timed out.}}, 
NSErrorFailingURLStringKey=<a href="https://tunnelblick.net/ipinfo" rel="nofollow">https://tunnelblick.net/ipinfo</a>, NSErrorFailingURLKey=<a href="https://tunnelblick.net/ipinfo" rel="nofollow">https://tunnelblick.net/ipinfo</a>,
 _kCFStreamErrorDomainKey=4, _kCFStreamErrorCodeKey=-2102, 
NSLocalizedDescription=The request timed out.}'; the response was 
'(null)'<br>2017-11-10 00:09:30 Tunnelblick[1595] 
currentIPInfo(Address): IP address info could not be fetched within 35.5
 seconds; the error was 'Error Domain=NSURLErrorDomain Code=-1001 "The 
request timed out." UserInfo={NSUnderlyingError=0x60000044cea0 {Error 
Domain=kCFErrorDomainCFNetwork Code=-1001 "The request timed out." 
UserInfo={NSErrorFailingURLStringKey=<a href="http://205.233.73.116/ipinfo" rel="nofollow">http://205.233.73.116/ipinfo</a>, NSErrorFailingURLKey=<a href="http://205.233.73.116/ipinfo" rel="nofollow">http://205.233.73.116/ipinfo</a>,
 _kCFStreamErrorCodeKey=-2102, _kCFStreamErrorDomainKey=4, 
NSLocalizedDescription=The request timed out.}}, 
NSErrorFailingURLStringKey=<a href="http://205.233.73.116/ipinfo" rel="nofollow">http://205.233.73.116/ipinfo</a>, NSErrorFailingURLKey=<a href="http://205.233.73.116/ipinfo" rel="nofollow">http://205.233.73.116/ipinfo</a>,
 _kCFStreamErrorDomainKey=4, _kCFStreamErrorCodeKey=-2102, 
NSLocalizedDescription=The request timed out.}'; the response was 
'(null)'</div></div>