Closed Bug 1409642 Opened 7 years ago Closed 7 years ago

External VPN stop working

Categories

(Infrastructure & Operations :: Corporate VPN: Support requests, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: timdream, Unassigned)

References

Details

The same external VPN configureation failed to connect internet through. TunnelBlink complains DNS failed to work.

===

*Tunnelblick: OS X 10.12.6; Tunnelblick 3.7.2a (build 4851); prior version 3.7.2 (build 4850); Admin user
git commit f4272d39fa0e2c16b1fbb00c2aaa96719526485c


Configuration Mozilla External VPN

"Sanitized" condensed configuration file for /Users/timdream/Library/Application Support/Tunnelblick/Configurations/Mozilla External VPN.tblk:

remote externalvpn.scl3.mozilla.com 1194 udp
remote externalvpn.scl3.mozilla.com 1194 tcp-client
remote externalvpn.scl3.mozilla.com 443 tcp-client
remote externalvpn.scl3.mozilla.com 80 tcp-client
auth-user-pass
persist-key
tls-client
tls-auth ta.key 1
pull
ca ca.crt
dev tun
persist-tun
cert cert.crt
comp-lzo no
nobind
key key.key
cipher AES-256-CBC
remote-cert-eku "TLS Web Server Authentication"
resolv-retry infinite
reneg-sec 2592000


================================================================================

Non-Apple kexts that are loaded:

Index Refs Address            Size       Wired      Name (Version) UUID <Linked Against>

================================================================================

There are no unusual files in Mozilla External VPN.tblk

================================================================================

Configuration preferences:

useDNS = 1
-routeAllTrafficThroughVpn = 0
-keychainHasUsername = 1
-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0
-lastConnectionSucceeded = 1

================================================================================

Wildcard preferences:

-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0

================================================================================

Program preferences:

skipWarningThatIPANotFetchedBeforeConnection = 1
skipWarningThatIPAddressDidNotChangeAfterConnection = 1
placeIconInStandardPositionInStatusBar = 1
launchAtNextLogin = 1
notOKToCheckThatIPAddressDidNotChangeAfterConnection = 0
askedUserIfOKToCheckThatIPAddressDidNotChangeAfterConnection = 1
tunnelblickVersionHistory = (
    "3.7.2a (build 4851)",
    "3.7.2 (build 4850)",
    "3.7.1b (build 4813)",
    "3.7.1a (build 4812)",
    "3.7.1 (build 4811)",
    "3.7.0 (build 4790)",
    "3.6.9 (build 4685)",
    "3.6.8 (build 4625)",
    "3.6.7a (build 4603)",
    "3.6.5 (build 4566)"
)
statusDisplayNumber = 0
lastLaunchTime = 528617817.839527
doNotShowConnectionSubmenus = 0
doNotShowSplashScreen = 1
showConnectedDurations = 1
lastLanguageAtLaunchWasRTL = 0
connectionWindowDisplayCriteria = showWhenConnecting
maxLogDisplaySize = 102400
lastConnectedDisplayName = Mozilla External VPN
keyboardShortcutIndex = 1
updateAutomatically = 0
updateCheckAutomatically = 1
updateSendProfileInfo = 0
NSWindow Frame ConnectingWindow = -1124 494 412 297 -1920 -30 1920 1057 
NSWindow Frame SUStatusFrame = -975 520 400 129 -1920 -30 1920 1057 
NSWindow Frame SUUpdateAlert = -1270 469 620 392 -1920 -30 1920 1057 
detailsWindowFrameVersion = 4812
detailsWindowFrame = {{380, 420}, {920, 468}}
detailsWindowLeftFrame = {{0, 0}, {165, 350}}
detailsWindowViewIndex = 0
detailsWindowConfigurationsTabIdentifier = log
leftNavSelectedDisplayName = Mozilla External VPN
AdvancedWindowTabIdentifier = connectingAndDisconnecting
haveDealtWithSparkle1dot5b6 = 1
haveDealtWithOldTunTapPreferences = 1
haveDealtWithOldLoginItem = 1
SUEnableAutomaticChecks = 1
SUFeedURL = https://www.tunnelblick.net/appcast-s.rss
SUScheduledCheckInterval = 86400
SUSendProfileInfo = 0
SUAutomaticallyUpdate = 0
SULastCheckTime = 2017-10-18 06:55:46 +0000
SUHasLaunchedBefore = 1
WebKitDefaultFontSize = 11
WebKitStandardFont = .AppleSystemUIFont
tunnelblickdHash = 004cdba8e08abd144bc48409040bc80e29c12ee9741ed7d73754f51d2547f7ea
tunnelblickdPlistHash = ce400d395d1801b003398461b5420021f4d591822783a04b79b2f43956d28620

================================================================================

Tunnelblick Log:

*Tunnelblick: OS X 10.12.6; Tunnelblick 3.7.2a (build 4851); prior version 3.7.2 (build 4850)
2017-10-18 15:06:33 *Tunnelblick: Attempting connection with Mozilla External VPN using shadow copy; Set nameserver = 769; monitoring connection
2017-10-18 15:06:33 *Tunnelblick: openvpnstart start Mozilla\ External\ VPN.tblk 1337 769 0 1 0 1065264 -ptADGNWradsgnw 2.3.18-openssl-1.0.2k
2017-10-18 15:06:33 *Tunnelblick: openvpnstart log:
     OpenVPN started successfully. Command used to start OpenVPN (one argument per displayed line):
     
          /Applications/Tunnelblick.app/Contents/Resources/openvpn/openvpn-2.3.18-openssl-1.0.2k/openvpn
          --daemon
          --log
          /Library/Application Support/Tunnelblick/Logs/-SUsers-Stimdream-SLibrary-SApplication Support-STunnelblick-SConfigurations-SMozilla External VPN.tblk-SContents-SResources-Sconfig.ovpn.769_0_1_0_1065264.1337.openvpn.log
          --cd
          /Library/Application Support/Tunnelblick/Users/timdream/Mozilla External VPN.tblk/Contents/Resources
          --verb
          3
          --config
          /Library/Application Support/Tunnelblick/Users/timdream/Mozilla External VPN.tblk/Contents/Resources/config.ovpn
          --verb
          3
          --cd
          /Library/Application Support/Tunnelblick/Users/timdream/Mozilla External VPN.tblk/Contents/Resources
          --management
          127.0.0.1
          1337
          --management-query-passwords
          --management-hold
          --script-security
          2
          --up
          /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw
          --down
          /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw

2017-10-18 15:06:33 *Tunnelblick: Established communication with OpenVPN
2017-10-18 15:06:33 OpenVPN 2.3.18 x86_64-apple-darwin [SSL (OpenSSL)] [LZO] [PKCS11] [MH] [IPv6] built on Sep 26 2017
2017-10-18 15:06:33 library versions: OpenSSL 1.0.2k  26 Jan 2017, LZO 2.09
2017-10-18 15:06:33 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:1337
2017-10-18 15:06:33 Need hold release from management interface, waiting...
2017-10-18 15:06:33 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:1337
2017-10-18 15:06:33 MANAGEMENT: CMD 'pid'
2017-10-18 15:06:33 MANAGEMENT: CMD 'state on'
2017-10-18 15:06:33 MANAGEMENT: CMD 'state'
2017-10-18 15:06:33 MANAGEMENT: CMD 'bytecount 1'
2017-10-18 15:06:33 MANAGEMENT: CMD 'hold release'
2017-10-18 15:06:33 *Tunnelblick: openvpnstart starting OpenVPN
2017-10-18 15:06:45 MANAGEMENT: CMD 'username "Auth" "tchien@mozilla.com"'
2017-10-18 15:06:45 MANAGEMENT: CMD 'password [...]'
2017-10-18 15:06:45 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-10-18 15:06:45 Control Channel Authentication: using 'ta.key' as a OpenVPN static key file
2017-10-18 15:06:45 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
2017-10-18 15:06:45 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
2017-10-18 15:06:45 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-10-18 15:06:45 MANAGEMENT: >STATE:1508310405,RESOLVE,,,
2017-10-18 15:06:45 UDPv4 link local: [undef]
2017-10-18 15:06:45 UDPv4 link remote: [AF_INET]63.245.214.136:1194
2017-10-18 15:06:45 MANAGEMENT: >STATE:1508310405,WAIT,,,
2017-10-18 15:06:45 MANAGEMENT: >STATE:1508310405,AUTH,,,
2017-10-18 15:06:45 TLS: Initial packet from [AF_INET]63.245.214.136:1194, sid=2db94a36 4fade5ed
2017-10-18 15:06:45 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
2017-10-18 15:06:46 VERIFY OK: depth=1, C=US, ST=California, L=Mountain View, O=Mozilla Corporation, OU=Mozilla Corporation Root Certificate Services, CN=Mozilla Root SHA-2 CA, emailAddress=hostmaster@mozilla.com
2017-10-18 15:06:46 Validating certificate extended key usage
2017-10-18 15:06:46 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
2017-10-18 15:06:46 VERIFY EKU OK
2017-10-18 15:06:46 VERIFY OK: depth=0, C=US, ST=California, L=Mountain View, O=Mozilla Corporation, OU=Mozilla OpenVPN, CN=externalvpn.scl3.mozilla.com
2017-10-18 15:06:48 Data Channel Encrypt: Cipher 'AES-256-CBC' initialized with 256 bit key
2017-10-18 15:06:48 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
2017-10-18 15:06:48 Data Channel Decrypt: Cipher 'AES-256-CBC' initialized with 256 bit key
2017-10-18 15:06:48 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
2017-10-18 15:06:48 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 4096 bit RSA
2017-10-18 15:06:48 [externalvpn.scl3.mozilla.com] Peer Connection Initiated with [AF_INET]63.245.214.136:1194
2017-10-18 15:06:49 MANAGEMENT: >STATE:1508310409,GET_CONFIG,,,
2017-10-18 15:06:50 SENT CONTROL [externalvpn.scl3.mozilla.com]: 'PUSH_REQUEST' (status=1)
2017-10-18 15:06:50 PUSH: Received control message: 'PUSH_REPLY,route 10.22.72.132 255.255.255.255,route 63.245.214.136 255.255.255.255 net_gateway,route 63.245.214.137 255.255.255.255 net_gateway,dhcp-option DNS 10.22.72.132,redirect-gateway def1,route 10.22.232.1,topology net30,ping 10,ping-restart 120,ifconfig 10.22.232.14 10.22.232.13'
2017-10-18 15:06:50 OPTIONS IMPORT: timers and/or timeouts modified
2017-10-18 15:06:50 OPTIONS IMPORT: --ifconfig/up options modified
2017-10-18 15:06:50 OPTIONS IMPORT: route options modified
2017-10-18 15:06:50 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
2017-10-18 15:06:50 Opening utun (connect(AF_SYS_CONTROL)): Resource busy
2017-10-18 15:06:50 Opening utun (connect(AF_SYS_CONTROL)): Resource busy
2017-10-18 15:06:50 Opened utun device utun2
2017-10-18 15:06:50 do_ifconfig, tt->ipv6=0, tt->did_ifconfig_ipv6_setup=0
2017-10-18 15:06:50 MANAGEMENT: >STATE:1508310410,ASSIGN_IP,,10.22.232.14,
2017-10-18 15:06:50 /sbin/ifconfig utun2 delete
                                        ifconfig: ioctl (SIOCDIFADDR): Can't assign requested address
2017-10-18 15:06:50 NOTE: Tried to delete pre-existing tun/tap instance -- No Problem if failure
2017-10-18 15:06:50 /sbin/ifconfig utun2 10.22.232.14 10.22.232.13 mtu 1500 netmask 255.255.255.255 up
2017-10-18 15:06:50 /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw utun2 1500 1558 10.22.232.14 10.22.232.13 init
                                        **********************************************
                                        Start of output from client.up.tunnelblick.sh
                                        Disabled IPv6 for 'iPhone'
                                        Disabled IPv6 for 'Apple USB Ethernet Adapter'
                                        Disabled IPv6 for 'Thunderbolt Ethernet'
                                        Disabled IPv6 for 'Bluetooth PAN 2'
                                        Disabled IPv6 for 'Wi-Fi'
                                        Retrieved from OpenVPN: name server(s) [ 10.22.72.132 ], search domain(s) [  ] and SMB server(s) [  ] and using default domain name [ openvpn ]
                                        Not aggregating ServerAddresses because running on OS X 10.6 or higher
                                        Setting search domains to 'openvpn' because running under OS X 10.6 or higher and the search domains were not set manually (or are allowed to be changed) and 'Prepend domain name to search domains' was not selected
                                        Saved the DNS and SMB configurations so they can be restored
                                        Changed DNS ServerAddresses setting from '10.247.75.120' to '10.22.72.132'
                                        Changed DNS SearchDomains setting from 'tpe1.mozilla.com mozilla.com' to 'openvpn'
                                        Changed DNS DomainName setting from 'corp.tpe1.mozilla.com' to 'openvpn'
                                        Did not change SMB NetBIOSName setting of ''
                                        Did not change SMB Workgroup setting of ''
                                        Did not change SMB WINSAddresses setting of ''
                                        DNS servers '10.22.72.132' will be used for DNS queries when the VPN is active
                                        NOTE: The DNS servers do not include any free public DNS servers known to Tunnelblick. This may cause DNS queries to fail or be intercepted or falsified even if they are directed through the VPN. Specify only known public DNS servers or DNS servers located on the VPN network to avoid such problems.
                                        Flushed the DNS cache via dscacheutil
                                        /usr/sbin/discoveryutil not present. Not flushing the DNS cache via discoveryutil
                                        Notified mDNSResponder that the DNS cache was flushed
                                        Setting up to monitor system configuration with process-network-changes
                                        End of output from client.up.tunnelblick.sh
                                        **********************************************
2017-10-18 15:06:54 /sbin/route add -net 63.245.214.136 10.247.24.1 255.255.255.255
                                        add net 63.245.214.136: gateway 10.247.24.1
2017-10-18 15:06:54 /sbin/route add -net 0.0.0.0 10.22.232.13 128.0.0.0
                                        add net 0.0.0.0: gateway 10.22.232.13
2017-10-18 15:06:54 /sbin/route add -net 128.0.0.0 10.22.232.13 128.0.0.0
                                        add net 128.0.0.0: gateway 10.22.232.13
2017-10-18 15:06:54 MANAGEMENT: >STATE:1508310414,ADD_ROUTES,,,
2017-10-18 15:06:54 /sbin/route add -net 10.22.72.132 10.22.232.13 255.255.255.255
                                        add net 10.22.72.132: gateway 10.22.232.13
2017-10-18 15:06:54 /sbin/route add -net 63.245.214.136 10.247.24.1 255.255.255.255
                                        route: writing to routing socket: File exists
                                        add net 63.245.214.136: gateway 10.247.24.1: File exists
2017-10-18 15:06:54 /sbin/route add -net 63.245.214.137 10.247.24.1 255.255.255.255
                                        add net 63.245.214.137: gateway 10.247.24.1
2017-10-18 15:06:54 /sbin/route add -net 10.22.232.1 10.22.232.13 255.255.255.255
                                        add net 10.22.232.1: gateway 10.22.232.13
2017-10-18 15:06:54 Initialization Sequence Completed
2017-10-18 15:06:54 MANAGEMENT: >STATE:1508310414,CONNECTED,SUCCESS,10.22.232.14,63.245.214.136
2017-10-18 15:06:55 *Tunnelblick: No 'connected.sh' script to execute

================================================================================

"Sanitized" full configuration file

#-- Config Auto Generated By Viscosity --#

#viscosity startonopen false
#viscosity dhcp true
#viscosity dnssupport true
#viscosity name Mozilla Certificate Based VPN

remote externalvpn.scl3.mozilla.com 1194 udp
remote externalvpn.scl3.mozilla.com 1194 tcp-client
remote externalvpn.scl3.mozilla.com 443 tcp-client
remote externalvpn.scl3.mozilla.com 80 tcp-client
#redirect-gateway def1

auth-user-pass
persist-key
tls-client
tls-auth ta.key 1
pull
ca ca.crt
dev tun
persist-tun
cert cert.crt
comp-lzo no
nobind
key key.key
cipher AES-256-CBC
remote-cert-eku "TLS Web Server Authentication"
resolv-retry infinite
reneg-sec 2592000



================================================================================

ifconfig output:

lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
	options=1203<RXCSUM,TXCSUM,TXSTATUS,SW_TIMESTAMP>
	inet 127.0.0.1 netmask 0xff000000 
	inet6 ::1 prefixlen 128 
	inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1 
	nd6 options=201<PERFORMNUD,DAD>
gif0: flags=8010<POINTOPOINT,MULTICAST> mtu 1280
stf0: flags=0<> mtu 1280
en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
	ether 4c:32:75:8d:10:1b 
	inet 10.247.28.48 netmask 0xfffff800 broadcast 10.247.31.255
	nd6 options=201<PERFORMNUD,DAD>
	media: autoselect
	status: active
en1: flags=963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX> mtu 1500
	options=60<TSO4,TSO6>
	ether 4a:00:06:71:5d:80 
	media: autoselect <full-duplex>
	status: inactive
en2: flags=963<UP,BROADCAST,SMART,RUNNING,PROMISC,SIMPLEX> mtu 1500
	options=60<TSO4,TSO6>
	ether 4a:00:06:71:5d:81 
	media: autoselect <full-duplex>
	status: inactive
bridge0: flags=8822<BROADCAST,SMART,SIMPLEX,MULTICAST> mtu 1500
	options=63<RXCSUM,TXCSUM,TSO4,TSO6>
	ether 4a:00:06:71:5d:80 
	Configuration:
		id 0:0:0:0:0:0 priority 0 hellotime 0 fwddelay 0
		maxage 0 holdcnt 0 proto stp maxaddr 100 timeout 1200
		root id 0:0:0:0:0:0 priority 0 ifcost 0 port 0
		ipfilter disabled flags 0x2
	member: en1 flags=3<LEARNING,DISCOVER>
	        ifmaxaddr 0 port 5 priority 0 path cost 0
	member: en2 flags=3<LEARNING,DISCOVER>
	        ifmaxaddr 0 port 6 priority 0 path cost 0
	media: <unknown type>
	status: inactive
p2p0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 2304
	ether 0e:32:75:8d:10:1b 
	media: autoselect
	status: inactive
awdl0: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> mtu 1484
	ether 1e:bf:cd:e3:31:74 
	inet6 fe80::1cbf:cdff:fee3:3174%awdl0 prefixlen 64 scopeid 0x9 
	nd6 options=201<PERFORMNUD,DAD>
	media: autoselect
	status: active
utun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 2000
	inet6 fe80::bb76:c542:e1a9:2822%utun0 prefixlen 64 scopeid 0xa 
	nd6 options=201<PERFORMNUD,DAD>
utun1: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1380
	inet6 fe80::8231:ff82:5839:a0c2%utun1 prefixlen 64 scopeid 0xb 
	nd6 options=201<PERFORMNUD,DAD>
utun2: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1500
	inet 10.22.232.14 --> 10.22.232.13 netmask 0xffffffff 

================================================================================

Console Log:

2017-10-18 14:55:12 Tunnelblick[10746] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-Mozilla External VPN' account = 'username'
2017-10-18 14:55:12 Tunnelblick[10746] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-Mozilla External VPN' account = 'username'
2017-10-18 14:55:45 Tunnelblick[10746] Can't find Keychain item to delete for service = 'Tunnelblick-Auth-Mozilla External VPN' account = 'password' because it does not exist
2017-10-18 14:55:46 Tunnelblick[10746] Sparkle: Verified appcast signature
2017-10-18 14:56:36 Tunnelblick[10746] currentIPInfo(Name): IP address info could not be fetched within 35.4 seconds; the error was 'Error Domain=NSURLErrorDomain Code=-1001 "The request timed out." UserInfo={NSUnderlyingError=0x608000055db0 {Error Domain=kCFErrorDomainCFNetwork Code=-1001 "The request timed out." UserInfo={NSErrorFailingURLStringKey=https://www.tunnelblick.net/ipinfo, NSErrorFailingURLKey=https://www.tunnelblick.net/ipinfo, _kCFStreamErrorCodeKey=-2102, _kCFStreamErrorDomainKey=4, NSLocalizedDescription=The request timed out.}}, NSErrorFailingURLStringKey=https://www.tunnelblick.net/ipinfo, NSErrorFailingURLKey=https://www.tunnelblick.net/ipinfo, _kCFStreamErrorDomainKey=4, _kCFStreamErrorCodeKey=-2102, NSLocalizedDescription=The request timed out.}'; the response was '(null)'
2017-10-18 15:01:38 Tunnelblick[10746] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-Mozilla External VPN' account = 'username'
2017-10-18 15:01:38 Tunnelblick[10746] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-Mozilla External VPN' account = 'username'
2017-10-18 15:01:49 Tunnelblick[10746] Can't find Keychain item to delete for service = 'Tunnelblick-Auth-Mozilla External VPN' account = 'password' because it does not exist
2017-10-18 15:02:39 Tunnelblick[10746] currentIPInfo(Name): IP address info could not be fetched within 35.4 seconds; the error was 'Error Domain=NSURLErrorDomain Code=-1001 "The request timed out." UserInfo={NSUnderlyingError=0x6080004581b0 {Error Domain=kCFErrorDomainCFNetwork Code=-1001 "The request timed out." UserInfo={NSErrorFailingURLStringKey=https://www.tunnelblick.net/ipinfo, NSErrorFailingURLKey=https://www.tunnelblick.net/ipinfo, _kCFStreamErrorCodeKey=-2102, _kCFStreamErrorDomainKey=4, NSLocalizedDescription=The request timed out.}}, NSErrorFailingURLStringKey=https://www.tunnelblick.net/ipinfo, NSErrorFailingURLKey=https://www.tunnelblick.net/ipinfo, _kCFStreamErrorDomainKey=4, _kCFStreamErrorCodeKey=-2102, NSLocalizedDescription=The request timed out.}'; the response was '(null)'
2017-10-18 15:03:26 Tunnelblick[10746] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-Mozilla External VPN' account = 'username'
2017-10-18 15:03:26 Tunnelblick[10746] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-Mozilla External VPN' account = 'username'
2017-10-18 15:03:43 Tunnelblick[10746] Can't find Keychain item to delete for service = 'Tunnelblick-Auth-Mozilla External VPN' account = 'password' because it does not exist
2017-10-18 15:03:59 Tunnelblick[10746] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-Mozilla External VPN' account = 'username'
2017-10-18 15:03:59 Tunnelblick[10746] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-Mozilla External VPN' account = 'username'
2017-10-18 15:04:04 Tunnelblick[10746] Can't find Keychain item to delete for service = 'Tunnelblick-Auth-Mozilla External VPN' account = 'password' because it does not exist
2017-10-18 15:06:34 Tunnelblick[10746] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-Mozilla External VPN' account = 'username'
2017-10-18 15:06:34 Tunnelblick[10746] Keychain item retrieved successfully for service = 'Tunnelblick-Auth-Mozilla External VPN' account = 'username'
2017-10-18 15:06:45 Tunnelblick[10746] Can't find Keychain item to delete for service = 'Tunnelblick-Auth-Mozilla External VPN' account = 'password' because it does not exist
It looks like the DNS server in use on the VPN machine experienced an update recently, which seems to have broken DNS lookups for VPN clients due to a change in the way it handles our specific configuration. I've made a change on the host temporarily, and this restored the service for me. Please let me know if this is working again for you now, and we'll see how soon we can put in a permanent fix, after reviewing the change.
I can verify that it have since fixed. Thanks!
Status: NEW → RESOLVED
Closed: 7 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.