New UBUNTU server 16.04: Openvpn routing and firewall setup -> HELP!

This forum is for admins who are looking to build or expand their OpenVPN setup.

Moderators: TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech

Forum rules
Please use the [oconf] BB tag for openvpn Configurations. See viewtopic.php?f=30&t=21589 for an example.
Post Reply
wowiesy
OpenVPN User
Posts: 25
Joined: Mon Jul 10, 2017 6:33 am

New UBUNTU server 16.04: Openvpn routing and firewall setup -> HELP!

Post by wowiesy » Mon Jul 10, 2017 7:14 am

Hi,

After years of using off-the-shelf SOHO routers, I've finally had to migrate to a "from-the-ground-up" server that will act as a home router / firewall. I've managed to get dnsmasq to serve DNS within the LAN, as well as DHCP..

using the SOHO router, my OPENVPN setup worked great when I access LAN services. However, due to the limitation of SOHO routers, I couldn't MASQUERADE the VPN IPs which prevented me from routing all internet traffic through the VPN, which means a lot to me whenever I travel to China 8-) =) (I am not sure if there really is a way to do that on SOHO routers, or if the functionality is just there hidden somewhere.. ) . Now that I am migrating to an UBUNTU server as router.. I am having issues. I think it is mostly routing and/or firewall issues...

ROUTER INFORMATION:
OS: UBUNTU 16.04 SERVER (installed ubuntu-desktop though)

WAN:
interface: enp2s0
ip address: 192.168.1.1 (thru DHCP from the provider modem)

LAN
interface: enp1s0
ip address: 192.168.254.1

services on the router/server:
SSH
DNS / DHCP (c/o dnsmasq)

OPENVPN SERVER (separate machine)
ip address: 192.168.254.254

OPENVPN SERVER routing table:

Code: Select all

Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
10.8.0.5        *               255.255.255.255 UH    0      0        0 tun2
10.6.1.2        *               255.255.255.255 UH    0      0        0 tun0
10.6.0.2        *               255.255.255.255 UH    0      0        0 tun1
192.168.100.0   10.8.0.5        255.255.255.0   UG    0      0        0 tun2
192.168.102.0   10.8.0.5        255.255.255.0   UG    0      0        0 tun2
10.6.1.0        10.6.1.2        255.255.255.0   UG    0      0        0 tun0
10.6.0.0        10.6.0.2        255.255.255.0   UG    0      0        0 tun1
10.8.0.0        10.8.0.5        255.255.255.0   UG    0      0        0 tun2
192.168.254.0   *               255.255.255.0   U     0      0        0 eth0
link-local      *               255.255.0.0     U     1000   0        0 eth0
default         u1010router.loc 0.0.0.0         UG    100    0        0 eth0
OPENSERVER iptables
filter table:

Code: Select all

Chain INPUT (policy ACCEPT 67546 packets, 12M bytes)
 pkts bytes target     prot opt in     out     source               destination         


Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         


Chain OUTPUT (policy ACCEPT 73033 packets, 6813K bytes)
 pkts bytes target     prot opt in     out     source               destination
nat table:

Code: Select all

Chain PREROUTING (policy ACCEPT 5215 packets, 205K bytes)
 pkts bytes target     prot opt in     out     source               destination         


Chain POSTROUTING (policy ACCEPT 3270 packets, 282K bytes)
 pkts bytes target     prot opt in     out     source               destination         


Chain OUTPUT (policy ACCEPT 3270 packets, 282K bytes)
 pkts bytes target     prot opt in     out     source               destination
SERVER CONFIG
server
port 1194
proto udp
dev tun
ca /etc/openvpn/ca.crt
cert /etc/openvpn/U1010SERVER.crt
key /etc/openvpn/U1010SERVER.key # This file should be kept secret
dh /etc/openvpn/dh1024.pem
server 10.6.0.0 255.255.255.0
ifconfig-pool-persist ipp.txt
push "route 192.168.254.0 255.255.255.0"
;push "dhcp-option DNS 208.67.222.222"
;push "dhcp-option DNS 208.67.220.220"
keepalive 10 120
tls-auth /etc/openvpn/ta.key 0 # This file is secret
;cipher BF-CBC # Blowfish (default)
;cipher AES-128-CBC # AES
;cipher DES-EDE3-CBC # Triple-DES
comp-lzo
;max-clients 100
user nobody
group nobody
persist-key
persist-tun
status openvpn-status.log
;log openvpn.log
;log-append openvpn.log
verb 6
;mute 20

OPENVPN CLIENT CONFIG
client
client
dev tun
proto udp
remote <<openvpn ip >> 1194
resolv-retry infinite
nobind
;user nobody
;group nobody
persist-key
persist-tun
;mute-replay-warnings
ca ca.crt
cert KSS1XMAC.crt
key KSS1XMAC.key
;ns-cert-type server
tls-auth ta.key 1
;cipher x
comp-lzo
verb 5
;mute 20

for the UBUNTU ROUTER:
routing table:

Code: Select all

Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
default         192.168.1.1     0.0.0.0         UG    0      0        0 enp2s0
10.6.0.0        192.168.254.254 255.255.255.0   UG    0      0        0 enp1s0
10.6.1.0        192.168.254.254 255.255.255.0   UG    0      0        0 enp1s0
10.8.0.0        10.8.0.5        255.255.255.0   UG    0      0        0 tun2
10.8.0.5        *               255.255.255.255 UH    0      0        0 tun2
link-local      *               255.255.0.0     U     1000   0        0 enp1s0
192.168.1.0     *               255.255.255.0   U     0      0        0 enp2s0
192.168.100.0   10.8.0.5        255.255.255.0   UG    0      0        0 tun2
192.168.102.0   10.8.0.5        255.255.255.0   UG    0      0        0 tun2
192.168.254.0   *               255.255.255.0   U     0      0        0 enp1s0
iptables filter

Code: Select all

Chain INPUT (policy ACCEPT 10696 packets, 4425K bytes)
 pkts bytes target     prot opt in     out     source               destination         


Chain FORWARD (policy ACCEPT 2635K packets, 2461M bytes)
 pkts bytes target     prot opt in     out     source               destination         


Chain OUTPUT (policy ACCEPT 9673 packets, 1017K bytes)
 pkts bytes target     prot opt in     out     source               destination         


Chain SSH_ROUTER (0 references)
 pkts bytes target     prot opt in     out     source               destination
nat table

Code: Select all

Chain PREROUTING (policy ACCEPT 5982 packets, 540K bytes)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 DNAT       udp  --  enp2s0 *       0.0.0.0/0            0.0.0.0/0            udp dpt:1194 to:192.168.254.254
    0     0 DNAT       udp  --  enp2s0 *       0.0.0.0/0            0.0.0.0/0            udp dpt:1195 to:192.168.254.254


Chain INPUT (policy ACCEPT 1663 packets, 132K bytes)
 pkts bytes target     prot opt in     out     source               destination         


Chain OUTPUT (policy ACCEPT 1907 packets, 136K bytes)
 pkts bytes target     prot opt in     out     source               destination         


Chain POSTROUTING (policy ACCEPT 243 packets, 22443 bytes)
 pkts bytes target     prot opt in     out     source               destination         
 5980  520K MASQUERADE  all  --  *      enp2s0  0.0.0.0/0            0.0.0.0/0           
    0     0 MASQUERADE  all  --  *      enp2s0  192.168.254.0/24     0.0.0.0/0           
    0     0 MASQUERADE  all  --  *      enp2s0  10.6.0.0/24          0.0.0.0/0           
    0     0 MASQUERADE  all  --  *      enp2s0  10.6.1.0/24          0.0.0.0/0
to recap.. within the LAN, when I connect to the OPENVPN server (changed the client config remote ip to the local OPENVPN SERVER ip), I am able to connect properly to the VPN... that tells me that configuration is okay..

however.. when I use a mobile device (not through WIFI within the LAN, but through the telecom provider) to connect to the OPENVPN server.. the connection isn't established.

I haven't mastered how to use wireshark.. but trying it out.. I "traced" that the router is passing the connection to the OPENVPN server through the router (both WAN and LAN interfaces have the UDP connection initiated by my mobile device.. I presume that was the router forwarding to the OPENVPN server)... but after that. I do not know what's happening anymore... the OPENVPN server is on UBUNTU 10.10 and I couldn't fix the issues to be able to install wireshark...

looking at the iptables result: I see that my POSTROUTING entries are redundant.. it hit the 0/0 line first (and jumped to masquerade).. essentially all packets will go to this line then .. so I think I need to change that..

what's kind of weird though... based on my understanding.. the iptables NAT counter PREROUTING chain should also reflect the number of packets that got matched by this line (assuming what I saw through wireshark was really the firewall doing DNAT to the OPENVPN server... however it is zero.. and yet my policy is ACCEPT.. and all the packet count is right there on the policy...

I've thought of installing another instance of OPENVPN on this same router/server... in the hopes of making it easier and simpler... (I might do that also).. but for the purpose of gaining an understanding of firewalls / iptables and how it works.. I think I want to figure this one out before I make a final decision on that...

hope somebody can point me to the right direction on how to make this work..

PS - another weird thing I discovered... last night when I had to check, I logged into the modem settings and I found a port forward setting there for UDP port 1194 and 1195 to an IP address 192.168.1.254 (the LAN side of this modem is 192.168.1.0/24)... but there is no 192.168.1.254 machine... only the router (IP 192.168.1.1)... this was the setup of this modem EVEN WHEN I WAS SUCCESSFULLY CONNECTING TO MY OPENVPN SERVER USING THE OLD SOHO ROUTER! and yet I was able to connect to it in the past... this may be a separate topic.. but shouldn't it be that when the modem has a port forward entry... and it doesn't match.. then at that point, I shouldn't be able to connect at all to my OPENVPN in the past right?

TinCanTech
OpenVPN Protagonist
Posts: 11137
Joined: Fri Jun 03, 2016 1:17 pm

Re: New UBUNTU server 16.04: Openvpn routing and firewall setup -> HELP!

Post by TinCanTech » Mon Jul 10, 2017 12:10 pm

No openvpn log files .. ?

Please see:
HOWTO: Request Help ! {2}

wowiesy
OpenVPN User
Posts: 25
Joined: Mon Jul 10, 2017 6:33 am

Re: New UBUNTU server 16.04: Openvpn routing and firewall setup -> HELP!

Post by wowiesy » Mon Jul 10, 2017 3:15 pm

sorry about that... the original server config didn't have provisions for log.. I updated it... and here they are so far:

openvpn when started up.. and when connecting from a client from within the same LAN (apologies.. the logs I think is logging the events from 3 different instances of OPENVPN within the same machine - each one using their own port; actually, 2 are servers, another one is a client connecting to another OPENVPN server) -- these are the setup I had when I was still using the SOHO router..

again.. the openvpn logs:

Code: Select all

Mon Jul 10 23:01:12 2017 us=369578 Current Parameter Settings:
Mon Jul 10 23:01:12 2017 us=369698   config = '/etc/openvpn/U1010SERVER-all.conf'
Mon Jul 10 23:01:12 2017 us=369728   mode = 1
Mon Jul 10 23:01:12 2017 us=369752   persist_config = DISABLED
Mon Jul 10 23:01:12 2017 us=369776   persist_mode = 1
Mon Jul 10 23:01:12 2017 us=369799   show_ciphers = DISABLED
Mon Jul 10 23:01:12 2017 us=369822   show_digests = DISABLED
Mon Jul 10 23:01:12 2017 us=369845   show_engines = DISABLED
Mon Jul 10 23:01:12 2017 us=369868   genkey = DISABLED
Mon Jul 10 23:01:12 2017 us=369891   key_pass_file = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=369915   show_tls_ciphers = DISABLED
Mon Jul 10 23:01:12 2017 us=369939 Connection profiles [default]:
Mon Jul 10 23:01:12 2017 us=369962   proto = udp
Mon Jul 10 23:01:12 2017 us=369985   local = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=370014   local_port = 1195
Mon Jul 10 23:01:12 2017 us=370039   remote = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=370063   remote_port = 1195
Mon Jul 10 23:01:12 2017 us=370085   remote_float = DISABLED
Mon Jul 10 23:01:12 2017 us=370108   bind_defined = DISABLED
Mon Jul 10 23:01:12 2017 us=370131   bind_local = ENABLED
Mon Jul 10 23:01:12 2017 us=370154   connect_retry_seconds = 5
Mon Jul 10 23:01:12 2017 us=370177   connect_timeout = 10
Mon Jul 10 23:01:12 2017 us=370211   connect_retry_max = 0
Mon Jul 10 23:01:12 2017 us=370235   socks_proxy_server = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=370258   socks_proxy_port = 0
Mon Jul 10 23:01:12 2017 us=370281   socks_proxy_retry = DISABLED
Mon Jul 10 23:01:12 2017 us=370308 Connection profiles END
Mon Jul 10 23:01:12 2017 us=370332   remote_random = DISABLED
Mon Jul 10 23:01:12 2017 us=370358   ipchange = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=370381   dev = 'tun'
Mon Jul 10 23:01:12 2017 us=370404   dev_type = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=370427   dev_node = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=370449   lladdr = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=370472   topology = 1
Mon Jul 10 23:01:12 2017 us=370495   tun_ipv6 = DISABLED
Mon Jul 10 23:01:12 2017 us=370518   ifconfig_local = '10.6.1.1'
Mon Jul 10 23:01:12 2017 us=370541   ifconfig_remote_netmask = '10.6.1.2'
Mon Jul 10 23:01:12 2017 us=370564   ifconfig_noexec = DISABLED
Mon Jul 10 23:01:12 2017 us=370587   ifconfig_nowarn = DISABLED
Mon Jul 10 23:01:12 2017 us=370610   shaper = 0
Mon Jul 10 23:01:12 2017 us=370633   tun_mtu = 1500
Mon Jul 10 23:01:12 2017 us=370655   tun_mtu_defined = ENABLED
Mon Jul 10 23:01:12 2017 us=370678   link_mtu = 1500
Mon Jul 10 23:01:12 2017 us=370701   link_mtu_defined = DISABLED
Mon Jul 10 23:01:12 2017 us=370724   tun_mtu_extra = 0
Mon Jul 10 23:01:12 2017 us=370747   tun_mtu_extra_defined = DISABLED
Mon Jul 10 23:01:12 2017 us=370770   fragment = 0
Mon Jul 10 23:01:12 2017 us=370793   mtu_discover_type = -1
Mon Jul 10 23:01:12 2017 us=370816   mtu_test = 0
Mon Jul 10 23:01:12 2017 us=370838   mlock = DISABLED
Mon Jul 10 23:01:12 2017 us=370861   keepalive_ping = 10
Mon Jul 10 23:01:12 2017 us=370884   keepalive_timeout = 120
Mon Jul 10 23:01:12 2017 us=370907   inactivity_timeout = 0
Mon Jul 10 23:01:12 2017 us=370930   ping_send_timeout = 10
Mon Jul 10 23:01:12 2017 us=370952   ping_rec_timeout = 240
Mon Jul 10 23:01:12 2017 us=370975   ping_rec_timeout_action = 2
Mon Jul 10 23:01:12 2017 us=370998   ping_timer_remote = DISABLED
Mon Jul 10 23:01:12 2017 us=371021   remap_sigusr1 = 0
Mon Jul 10 23:01:12 2017 us=371044   explicit_exit_notification = 0
Mon Jul 10 23:01:12 2017 us=371066   persist_tun = ENABLED
Mon Jul 10 23:01:12 2017 us=371089   persist_local_ip = DISABLED
Mon Jul 10 23:01:12 2017 us=371112   persist_remote_ip = DISABLED
Mon Jul 10 23:01:12 2017 us=371135   persist_key = ENABLED
Mon Jul 10 23:01:12 2017 us=371157   mssfix = 1450
Mon Jul 10 23:01:12 2017 us=371180   passtos = DISABLED
Mon Jul 10 23:01:12 2017 us=371203   resolve_retry_seconds = 1000000000
Mon Jul 10 23:01:12 2017 us=371226   username = 'nobody'
Mon Jul 10 23:01:12 2017 us=371248   groupname = 'nobody'
Mon Jul 10 23:01:12 2017 us=371271   chroot_dir = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=371304   cd_dir = '/etc/openvpn'
Mon Jul 10 23:01:12 2017 us=371328   writepid = '/var/run/openvpn.U1010SERVER-all.pid'
Mon Jul 10 23:01:12 2017 us=371351   up_script = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=371374   down_script = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=371396   down_pre = DISABLED
Mon Jul 10 23:01:12 2017 us=371419   up_restart = DISABLED
Mon Jul 10 23:01:12 2017 us=371442   up_delay = DISABLED
Mon Jul 10 23:01:12 2017 us=371464   daemon = ENABLED
Mon Jul 10 23:01:12 2017 us=371487   inetd = 0
Mon Jul 10 23:01:12 2017 us=371510   log = ENABLED
Mon Jul 10 23:01:12 2017 us=371533   suppress_timestamps = DISABLED
Mon Jul 10 23:01:12 2017 us=371556   nice = 0
Mon Jul 10 23:01:12 2017 us=371579   verbosity = 6
Mon Jul 10 23:01:12 2017 us=371602   mute = 0
Mon Jul 10 23:01:12 2017 us=371625   gremlin = 0
Mon Jul 10 23:01:12 2017 us=371648   status_file = 'openvpn-status.log'
Mon Jul 10 23:01:12 2017 us=371671   status_file_version = 1
Mon Jul 10 23:01:12 2017 us=371694   status_file_update_freq = 60
Mon Jul 10 23:01:12 2017 us=371717   occ = ENABLED
Mon Jul 10 23:01:12 2017 us=371740   rcvbuf = 65536
Mon Jul 10 23:01:12 2017 us=371763   sndbuf = 65536
Mon Jul 10 23:01:12 2017 us=371785   sockflags = 0
Mon Jul 10 23:01:12 2017 us=371808   fast_io = DISABLED
Mon Jul 10 23:01:12 2017 us=371831   lzo = 7
Mon Jul 10 23:01:12 2017 us=371854   route_script = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=371877   route_default_gateway = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=371900   route_default_metric = 0
Mon Jul 10 23:01:12 2017 us=371923   route_noexec = DISABLED
Mon Jul 10 23:01:12 2017 us=371946   route_delay = 0
Mon Jul 10 23:01:12 2017 us=371969   route_delay_window = 30
Mon Jul 10 23:01:12 2017 us=371992   route_delay_defined = DISABLED
Mon Jul 10 23:01:12 2017 us=372015   route_nopull = DISABLED
Mon Jul 10 23:01:12 2017 us=372038   route_gateway_via_dhcp = DISABLED
Mon Jul 10 23:01:12 2017 us=372061   max_routes = 100
Mon Jul 10 23:01:12 2017 us=372085   allow_pull_fqdn = DISABLED
Mon Jul 10 23:01:12 2017 us=372109   route 10.6.1.0/255.255.255.0/nil/nil
Mon Jul 10 23:01:12 2017 us=372133   management_addr = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=372156   management_port = 0
Mon Jul 10 23:01:12 2017 us=372179   management_user_pass = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=372202   management_log_history_cache = 250
Mon Jul 10 23:01:12 2017 us=372226   management_echo_buffer_size = 100
Mon Jul 10 23:01:12 2017 us=372249   management_write_peer_info_file = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=372273   management_client_user = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=372296   management_client_group = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=372319   management_flags = 0
Mon Jul 10 23:01:12 2017 us=372342   shared_secret_file = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=372365   key_direction = 1
Mon Jul 10 23:01:12 2017 us=372387   ciphername_defined = ENABLED
Mon Jul 10 23:01:12 2017 us=372410   ciphername = 'BF-CBC'
Mon Jul 10 23:01:12 2017 us=372433   authname_defined = ENABLED
Mon Jul 10 23:01:12 2017 us=372456   authname = 'SHA1'
Mon Jul 10 23:01:12 2017 us=372479   prng_hash = 'SHA1'
Mon Jul 10 23:01:12 2017 us=372502   prng_nonce_secret_len = 16
Mon Jul 10 23:01:12 2017 us=372526   keysize = 0
Mon Jul 10 23:01:12 2017 us=372549   engine = DISABLED
Mon Jul 10 23:01:12 2017 us=372572   replay = ENABLED
Mon Jul 10 23:01:12 2017 us=372595   mute_replay_warnings = DISABLED
Mon Jul 10 23:01:12 2017 us=372618   replay_window = 64
Mon Jul 10 23:01:12 2017 us=372641   replay_time = 15
Mon Jul 10 23:01:12 2017 us=372664   packet_id_file = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=372687   use_iv = ENABLED
Mon Jul 10 23:01:12 2017 us=372709   test_crypto = DISABLED
Mon Jul 10 23:01:12 2017 us=372732   tls_server = ENABLED
Mon Jul 10 23:01:12 2017 us=372754   tls_client = DISABLED
Mon Jul 10 23:01:12 2017 us=372777   key_method = 2
Mon Jul 10 23:01:12 2017 us=372800   ca_file = '/etc/openvpn/ca.crt'
Mon Jul 10 23:01:12 2017 us=372822   ca_path = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=372846   dh_file = '/etc/openvpn/dh1024.pem'
Mon Jul 10 23:01:12 2017 us=372878   cert_file = '/etc/openvpn/U1010SERVER.crt'
Mon Jul 10 23:01:12 2017 us=372903   priv_key_file = '/etc/openvpn/U1010SERVER.key'
Mon Jul 10 23:01:12 2017 us=372926   pkcs12_file = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=372949   cipher_list = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=372971   tls_verify = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=372995   tls_export_cert = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=373018   tls_remote = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=373041   crl_file = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=373064   ns_cert_type = 0
Mon Jul 10 23:01:12 2017 us=373087   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=373110   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=373133   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=373156   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=373179   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=373202   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=373225   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=373247   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=373270   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=373293   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=373316   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=373339   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=373362   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=373385   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=373408   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=373431   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=373454   remote_cert_eku = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=373477   tls_timeout = 2
Mon Jul 10 23:01:12 2017 us=373500   renegotiate_bytes = 0
Mon Jul 10 23:01:12 2017 us=373522   renegotiate_packets = 0
Mon Jul 10 23:01:12 2017 us=373546   renegotiate_seconds = 3600
Mon Jul 10 23:01:12 2017 us=373569   handshake_window = 60
Mon Jul 10 23:01:12 2017 us=373592   transition_window = 3600
Mon Jul 10 23:01:12 2017 us=373615   single_session = DISABLED
Mon Jul 10 23:01:12 2017 us=373638   push_peer_info = DISABLED
Mon Jul 10 23:01:12 2017 us=373661   tls_exit = DISABLED
Mon Jul 10 23:01:12 2017 us=373684   tls_auth_file = '/etc/openvpn/ta.key'
Mon Jul 10 23:01:12 2017 us=373709   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=373732   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=373756   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=373779   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=373802   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=373825   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=373848   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=373871   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=373894   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=373917   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=373940   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=373963   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=373986   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=374009   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=374032   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=374055   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=374079   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=374102   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=374125   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=374148   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=374171   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=374194   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=374244   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=374268   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=374291   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=374324   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=374348   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=374371   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=374394   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=374418   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=374441   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=374464   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=374487   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=374510   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=374533   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=374556   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=374579   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=374602   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=374625   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=374648   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=374671   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=374694   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=374717   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=374739   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=374763   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=374786   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=374808   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=374832   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=374855   pkcs11_pin_cache_period = -1
Mon Jul 10 23:01:12 2017 us=374878   pkcs11_id = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=374900   pkcs11_id_management = DISABLED
Mon Jul 10 23:01:12 2017 us=374926   server_network = 10.6.1.0
Mon Jul 10 23:01:12 2017 us=374952   server_netmask = 255.255.255.0
Mon Jul 10 23:01:12 2017 us=374977   server_bridge_ip = 0.0.0.0
Mon Jul 10 23:01:12 2017 us=375007   server_bridge_netmask = 0.0.0.0
Mon Jul 10 23:01:12 2017 us=375034   server_bridge_pool_start = 0.0.0.0
Mon Jul 10 23:01:12 2017 us=375059   server_bridge_pool_end = 0.0.0.0
Mon Jul 10 23:01:12 2017 us=375082   push_entry = 'route 192.168.254.0 255.255.255.0'
Mon Jul 10 23:01:12 2017 us=375106   push_entry = 'redirect-gateway def1 bypass-dhcp'
Mon Jul 10 23:01:12 2017 us=375129   push_entry = 'route 10.6.1.1'
Mon Jul 10 23:01:12 2017 us=375152   push_entry = 'topology net30'
Mon Jul 10 23:01:12 2017 us=375175   push_entry = 'ping 10'
Mon Jul 10 23:01:12 2017 us=375198   push_entry = 'ping-restart 120'
Mon Jul 10 23:01:12 2017 us=375221   ifconfig_pool_defined = ENABLED
Mon Jul 10 23:01:12 2017 us=375246   ifconfig_pool_start = 10.6.1.4
Mon Jul 10 23:01:12 2017 us=375271   ifconfig_pool_end = 10.6.1.251
Mon Jul 10 23:01:12 2017 us=375296   ifconfig_pool_netmask = 0.0.0.0
Mon Jul 10 23:01:12 2017 us=375319   ifconfig_pool_persist_filename = 'ipp.txt'
Mon Jul 10 23:01:12 2017 us=375342   ifconfig_pool_persist_refresh_freq = 600
Mon Jul 10 23:01:12 2017 us=375366   n_bcast_buf = 256
Mon Jul 10 23:01:12 2017 us=375388   tcp_queue_limit = 64
Mon Jul 10 23:01:12 2017 us=375411   real_hash_size = 256
Mon Jul 10 23:01:12 2017 us=375434   virtual_hash_size = 256
Mon Jul 10 23:01:12 2017 us=375457   client_connect_script = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=375480   learn_address_script = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=375504   client_disconnect_script = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=375527   client_config_dir = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=375550   ccd_exclusive = DISABLED
Mon Jul 10 23:01:12 2017 us=375573   tmp_dir = '/tmp'
Mon Jul 10 23:01:12 2017 us=375596   push_ifconfig_defined = DISABLED
Mon Jul 10 23:01:12 2017 us=375621   push_ifconfig_local = 0.0.0.0
Mon Jul 10 23:01:12 2017 us=375646   push_ifconfig_remote_netmask = 0.0.0.0
Mon Jul 10 23:01:12 2017 us=375669   enable_c2c = DISABLED
Mon Jul 10 23:01:12 2017 us=375692   duplicate_cn = DISABLED
Mon Jul 10 23:01:12 2017 us=375715   cf_max = 0
Mon Jul 10 23:01:12 2017 us=375737   cf_per = 0
Mon Jul 10 23:01:12 2017 us=375769   max_clients = 1024
Mon Jul 10 23:01:12 2017 us=375793   max_routes_per_client = 256
Mon Jul 10 23:01:12 2017 us=375816   auth_user_pass_verify_script = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=375839   auth_user_pass_verify_script_via_file = DISABLED
Mon Jul 10 23:01:12 2017 us=375862   ssl_flags = 0
Mon Jul 10 23:01:12 2017 us=375885   port_share_host = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=375908   port_share_port = 0
Mon Jul 10 23:01:12 2017 us=375930   client = DISABLED
Mon Jul 10 23:01:12 2017 us=375953   pull = DISABLED
Mon Jul 10 23:01:12 2017 us=375976   auth_user_pass_file = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=376004 OpenVPN 2.2.1 i486-linux-gnu [SSL] [LZO2] [EPOLL] [PKCS11] [eurephia] built on Jul  1 2011
Mon Jul 10 23:01:12 2017 us=376284 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Mon Jul 10 23:01:12 2017 us=382637 Diffie-Hellman initialized with 1024 bit key
Mon Jul 10 23:01:12 2017 us=383173 WARNING: file '/etc/openvpn/ta.key' is group or others accessible
Mon Jul 10 23:01:12 2017 us=383186 Control Channel Authentication: using '/etc/openvpn/ta.key' as a OpenVPN static key file
Mon Jul 10 23:01:12 2017 us=383203 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Jul 10 23:01:12 2017 us=383215 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Jul 10 23:01:12 2017 us=383238 TLS-Auth MTU parms [ L:1542 D:166 EF:66 EB:0 ET:0 EL:0 ]
Mon Jul 10 23:01:12 2017 us=383266 Socket Buffers: R=[112640->131072] S=[112640->131072]
Mon Jul 10 23:01:12 2017 us=383359 ROUTE default_gateway=192.168.254.1
Mon Jul 10 23:01:12 2017 us=384698 TUN/TAP device tun0 opened
Mon Jul 10 23:01:12 2017 us=384739 TUN/TAP TX queue length set to 100
Mon Jul 10 23:01:12 2017 us=384782 /sbin/ifconfig tun0 10.6.1.1 pointopoint 10.6.1.2 mtu 1500
Mon Jul 10 23:01:12 2017 us=386087 /sbin/route add -net 10.6.1.0 netmask 255.255.255.0 gw 10.6.1.2
Mon Jul 10 23:01:12 2017 us=386725 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Mon Jul 10 23:01:12 2017 us=387334 GID set to nobody
Mon Jul 10 23:01:12 2017 us=387402 UID set to nobody
Mon Jul 10 23:01:12 2017 us=387433 UDPv4 link local (bound): [undef]:1195
Mon Jul 10 23:01:12 2017 us=387446 UDPv4 link remote: [undef]
Mon Jul 10 23:01:12 2017 us=387463 MULTI: multi_init called, r=256 v=256
Mon Jul 10 23:01:12 2017 us=387544 IFCONFIG POOL: base=10.6.1.4 size=62
Mon Jul 10 23:01:12 2017 us=387569 IFCONFIG POOL LIST
Mon Jul 10 23:01:12 2017 us=387601 Initialization Sequence Completed
Mon Jul 10 23:01:12 2017 us=399808 Current Parameter Settings:
Mon Jul 10 23:01:12 2017 us=399871   config = '/etc/openvpn/U1010SERVER.conf'
Mon Jul 10 23:01:12 2017 us=399883   mode = 1
Mon Jul 10 23:01:12 2017 us=399893   persist_config = DISABLED
Mon Jul 10 23:01:12 2017 us=399903   persist_mode = 1
Mon Jul 10 23:01:12 2017 us=399913   show_ciphers = DISABLED
Mon Jul 10 23:01:12 2017 us=399923   show_digests = DISABLED
Mon Jul 10 23:01:12 2017 us=399933   show_engines = DISABLED
Mon Jul 10 23:01:12 2017 us=399943   genkey = DISABLED
Mon Jul 10 23:01:12 2017 us=399953   key_pass_file = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=399963   show_tls_ciphers = DISABLED
Mon Jul 10 23:01:12 2017 us=399973 Connection profiles [default]:
Mon Jul 10 23:01:12 2017 us=399983   proto = udp
Mon Jul 10 23:01:12 2017 us=399993   local = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=400004   local_port = 1194
Mon Jul 10 23:01:12 2017 us=400014   remote = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=400024   remote_port = 1194
Mon Jul 10 23:01:12 2017 us=400034   remote_float = DISABLED
Mon Jul 10 23:01:12 2017 us=400043   bind_defined = DISABLED
Mon Jul 10 23:01:12 2017 us=400053   bind_local = ENABLED
Mon Jul 10 23:01:12 2017 us=400063   connect_retry_seconds = 5
Mon Jul 10 23:01:12 2017 us=400073   connect_timeout = 10
Mon Jul 10 23:01:12 2017 us=400083   connect_retry_max = 0
Mon Jul 10 23:01:12 2017 us=400093   socks_proxy_server = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=400113   socks_proxy_port = 0
Mon Jul 10 23:01:12 2017 us=400123   socks_proxy_retry = DISABLED
Mon Jul 10 23:01:12 2017 us=400135 Connection profiles END
Mon Jul 10 23:01:12 2017 us=400145   remote_random = DISABLED
Mon Jul 10 23:01:12 2017 us=400156   ipchange = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=400169   dev = 'tun'
Mon Jul 10 23:01:12 2017 us=400180   dev_type = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=400190   dev_node = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=400200   lladdr = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=400210   topology = 1
Mon Jul 10 23:01:12 2017 us=400220   tun_ipv6 = DISABLED
Mon Jul 10 23:01:12 2017 us=400230   ifconfig_local = '10.6.0.1'
Mon Jul 10 23:01:12 2017 us=400240   ifconfig_remote_netmask = '10.6.0.2'
Mon Jul 10 23:01:12 2017 us=400250   ifconfig_noexec = DISABLED
Mon Jul 10 23:01:12 2017 us=400260   ifconfig_nowarn = DISABLED
Mon Jul 10 23:01:12 2017 us=400270   shaper = 0
Mon Jul 10 23:01:12 2017 us=400280   tun_mtu = 1500
Mon Jul 10 23:01:12 2017 us=400290   tun_mtu_defined = ENABLED
Mon Jul 10 23:01:12 2017 us=400300   link_mtu = 1500
Mon Jul 10 23:01:12 2017 us=400310   link_mtu_defined = DISABLED
Mon Jul 10 23:01:12 2017 us=400320   tun_mtu_extra = 0
Mon Jul 10 23:01:12 2017 us=400330   tun_mtu_extra_defined = DISABLED
Mon Jul 10 23:01:12 2017 us=400340   fragment = 0
Mon Jul 10 23:01:12 2017 us=400350   mtu_discover_type = -1
Mon Jul 10 23:01:12 2017 us=400360   mtu_test = 0
Mon Jul 10 23:01:12 2017 us=400369   mlock = DISABLED
Mon Jul 10 23:01:12 2017 us=400379   keepalive_ping = 10
Mon Jul 10 23:01:12 2017 us=400389   keepalive_timeout = 120
Mon Jul 10 23:01:12 2017 us=400399   inactivity_timeout = 0
Mon Jul 10 23:01:12 2017 us=400409   ping_send_timeout = 10
Mon Jul 10 23:01:12 2017 us=400419   ping_rec_timeout = 240
Mon Jul 10 23:01:12 2017 us=400429   ping_rec_timeout_action = 2
Mon Jul 10 23:01:12 2017 us=400439   ping_timer_remote = DISABLED
Mon Jul 10 23:01:12 2017 us=400449   remap_sigusr1 = 0
Mon Jul 10 23:01:12 2017 us=400459   explicit_exit_notification = 0
Mon Jul 10 23:01:12 2017 us=400469   persist_tun = ENABLED
Mon Jul 10 23:01:12 2017 us=400479   persist_local_ip = DISABLED
Mon Jul 10 23:01:12 2017 us=400488   persist_remote_ip = DISABLED
Mon Jul 10 23:01:12 2017 us=400498   persist_key = ENABLED
Mon Jul 10 23:01:12 2017 us=400508   mssfix = 1450
Mon Jul 10 23:01:12 2017 us=400518   passtos = DISABLED
Mon Jul 10 23:01:12 2017 us=400528   resolve_retry_seconds = 1000000000
Mon Jul 10 23:01:12 2017 us=400538   username = 'nobody'
Mon Jul 10 23:01:12 2017 us=400548   groupname = 'nobody'
Mon Jul 10 23:01:12 2017 us=400558   chroot_dir = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=400568   cd_dir = '/etc/openvpn'
Mon Jul 10 23:01:12 2017 us=400578   writepid = '/var/run/openvpn.U1010SERVER.pid'
Mon Jul 10 23:01:12 2017 us=400588   up_script = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=400597   down_script = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=400607   down_pre = DISABLED
Mon Jul 10 23:01:12 2017 us=400617   up_restart = DISABLED
Mon Jul 10 23:01:12 2017 us=400627   up_delay = DISABLED
Mon Jul 10 23:01:12 2017 us=400637   daemon = ENABLED
Mon Jul 10 23:01:12 2017 us=400647   inetd = 0
Mon Jul 10 23:01:12 2017 us=400656   log = ENABLED
Mon Jul 10 23:01:12 2017 us=400666   suppress_timestamps = DISABLED
Mon Jul 10 23:01:12 2017 us=400676   nice = 0
Mon Jul 10 23:01:12 2017 us=400686   verbosity = 6
Mon Jul 10 23:01:12 2017 us=400696   mute = 0
Mon Jul 10 23:01:12 2017 us=400706   gremlin = 0
Mon Jul 10 23:01:12 2017 us=400716   status_file = 'openvpn-status.log'
Mon Jul 10 23:01:12 2017 us=400726   status_file_version = 1
Mon Jul 10 23:01:12 2017 us=400735   status_file_update_freq = 60
Mon Jul 10 23:01:12 2017 us=400745   occ = ENABLED
Mon Jul 10 23:01:12 2017 us=400755   rcvbuf = 65536
Mon Jul 10 23:01:12 2017 us=400765   sndbuf = 65536
Mon Jul 10 23:01:12 2017 us=400775   sockflags = 0
Mon Jul 10 23:01:12 2017 us=400785   fast_io = DISABLED
Mon Jul 10 23:01:12 2017 us=400795   lzo = 7
Mon Jul 10 23:01:12 2017 us=400804   route_script = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=400819   route_default_gateway = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=400830   route_default_metric = 0
Mon Jul 10 23:01:12 2017 us=400839   route_noexec = DISABLED
Mon Jul 10 23:01:12 2017 us=400849   route_delay = 0
Mon Jul 10 23:01:12 2017 us=400859   route_delay_window = 30
Mon Jul 10 23:01:12 2017 us=400869   route_delay_defined = DISABLED
Mon Jul 10 23:01:12 2017 us=400879   route_nopull = DISABLED
Mon Jul 10 23:01:12 2017 us=400889   route_gateway_via_dhcp = DISABLED
Mon Jul 10 23:01:12 2017 us=400899   max_routes = 100
Mon Jul 10 23:01:12 2017 us=400909   allow_pull_fqdn = DISABLED
Mon Jul 10 23:01:12 2017 us=400920   route 10.6.0.0/255.255.255.0/nil/nil
Mon Jul 10 23:01:12 2017 us=400930   management_addr = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=400940   management_port = 0
Mon Jul 10 23:01:12 2017 us=400950   management_user_pass = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=400960   management_log_history_cache = 250
Mon Jul 10 23:01:12 2017 us=400970   management_echo_buffer_size = 100
Mon Jul 10 23:01:12 2017 us=400980   management_write_peer_info_file = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=400990   management_client_user = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=401001   management_client_group = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=401011   management_flags = 0
Mon Jul 10 23:01:12 2017 us=401021   shared_secret_file = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=401031   key_direction = 1
Mon Jul 10 23:01:12 2017 us=401041   ciphername_defined = ENABLED
Mon Jul 10 23:01:12 2017 us=401051   ciphername = 'BF-CBC'
Mon Jul 10 23:01:12 2017 us=401061   authname_defined = ENABLED
Mon Jul 10 23:01:12 2017 us=401071   authname = 'SHA1'
Mon Jul 10 23:01:12 2017 us=401081   prng_hash = 'SHA1'
Mon Jul 10 23:01:12 2017 us=401091   prng_nonce_secret_len = 16
Mon Jul 10 23:01:12 2017 us=401101   keysize = 0
Mon Jul 10 23:01:12 2017 us=401111   engine = DISABLED
Mon Jul 10 23:01:12 2017 us=401121   replay = ENABLED
Mon Jul 10 23:01:12 2017 us=401130   mute_replay_warnings = DISABLED
Mon Jul 10 23:01:12 2017 us=401140   replay_window = 64
Mon Jul 10 23:01:12 2017 us=401150   replay_time = 15
Mon Jul 10 23:01:12 2017 us=401160   packet_id_file = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=401170   use_iv = ENABLED
Mon Jul 10 23:01:12 2017 us=401180   test_crypto = DISABLED
Mon Jul 10 23:01:12 2017 us=401190   tls_server = ENABLED
Mon Jul 10 23:01:12 2017 us=401200   tls_client = DISABLED
Mon Jul 10 23:01:12 2017 us=401210   key_method = 2
Mon Jul 10 23:01:12 2017 us=401219   ca_file = '/etc/openvpn/ca.crt'
Mon Jul 10 23:01:12 2017 us=401229   ca_path = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=401239   dh_file = '/etc/openvpn/dh1024.pem'
Mon Jul 10 23:01:12 2017 us=401249   cert_file = '/etc/openvpn/U1010SERVER.crt'
Mon Jul 10 23:01:12 2017 us=401259   priv_key_file = '/etc/openvpn/U1010SERVER.key'
Mon Jul 10 23:01:12 2017 us=401269   pkcs12_file = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=401279   cipher_list = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=401289   tls_verify = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=401299   tls_export_cert = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=401309   tls_remote = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=401319   crl_file = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=401329   ns_cert_type = 0
Mon Jul 10 23:01:12 2017 us=401339   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=401349   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=401359   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=401369   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=401379   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=401389   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=401398   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=401408   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=401418   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=401428   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=401438   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=401447   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=401457   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=401467   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=401482   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=401492   remote_cert_ku[i] = 0
Mon Jul 10 23:01:12 2017 us=401502   remote_cert_eku = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=401512   tls_timeout = 2
Mon Jul 10 23:01:12 2017 us=401522   renegotiate_bytes = 0
Mon Jul 10 23:01:12 2017 us=401532   renegotiate_packets = 0
Mon Jul 10 23:01:12 2017 us=401542   renegotiate_seconds = 3600
Mon Jul 10 23:01:12 2017 us=401552   handshake_window = 60
Mon Jul 10 23:01:12 2017 us=401562   transition_window = 3600
Mon Jul 10 23:01:12 2017 us=401572   single_session = DISABLED
Mon Jul 10 23:01:12 2017 us=401582   push_peer_info = DISABLED
Mon Jul 10 23:01:12 2017 us=401592   tls_exit = DISABLED
Mon Jul 10 23:01:12 2017 us=401602   tls_auth_file = '/etc/openvpn/ta.key'
Mon Jul 10 23:01:12 2017 us=401612   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=401622   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=401632   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=401642   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=401652   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=401662   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=401673   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=401683   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=401693   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=401750   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=401760   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=401771   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=401781   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=401791   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=401801   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=401811   pkcs11_protected_authentication = DISABLED
Mon Jul 10 23:01:12 2017 us=401822   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=401832   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=401842   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=401852   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=401862   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=401872   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=401882   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=401892   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=401903   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=401913   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=401923   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=401933   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=401943   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=401953   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=401964   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=401974   pkcs11_private_mode = 00000000
Mon Jul 10 23:01:12 2017 us=401984   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=401994   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=402004   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=402014   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=402024   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=402034   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=402044   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=402054   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=402064   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=402074   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=402084   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=402094   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=402104   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=402114   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=402129   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=402140   pkcs11_cert_private = DISABLED
Mon Jul 10 23:01:12 2017 us=402150   pkcs11_pin_cache_period = -1
Mon Jul 10 23:01:12 2017 us=402160   pkcs11_id = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=402170   pkcs11_id_management = DISABLED
Mon Jul 10 23:01:12 2017 us=402181   server_network = 10.6.0.0
Mon Jul 10 23:01:12 2017 us=402192   server_netmask = 255.255.255.0
Mon Jul 10 23:01:12 2017 us=402203   server_bridge_ip = 0.0.0.0
Mon Jul 10 23:01:12 2017 us=402234   server_bridge_netmask = 0.0.0.0
Mon Jul 10 23:01:12 2017 us=402259   server_bridge_pool_start = 0.0.0.0
Mon Jul 10 23:01:12 2017 us=402285   server_bridge_pool_end = 0.0.0.0
Mon Jul 10 23:01:12 2017 us=402309   push_entry = 'route 192.168.254.0 255.255.255.0'
Mon Jul 10 23:01:12 2017 us=402332   push_entry = 'route 10.6.0.1'
Mon Jul 10 23:01:12 2017 us=402356   push_entry = 'topology net30'
Mon Jul 10 23:01:12 2017 us=402379   push_entry = 'ping 10'
Mon Jul 10 23:01:12 2017 us=402402   push_entry = 'ping-restart 120'
Mon Jul 10 23:01:12 2017 us=402426   ifconfig_pool_defined = ENABLED
Mon Jul 10 23:01:12 2017 us=402452   ifconfig_pool_start = 10.6.0.4
Mon Jul 10 23:01:12 2017 us=402478   ifconfig_pool_end = 10.6.0.251
Mon Jul 10 23:01:12 2017 us=402504   ifconfig_pool_netmask = 0.0.0.0
Mon Jul 10 23:01:12 2017 us=402527   ifconfig_pool_persist_filename = 'ipp.txt'
Mon Jul 10 23:01:12 2017 us=402551   ifconfig_pool_persist_refresh_freq = 600
Mon Jul 10 23:01:12 2017 us=402575   n_bcast_buf = 256
Mon Jul 10 23:01:12 2017 us=402598   tcp_queue_limit = 64
Mon Jul 10 23:01:12 2017 us=402621   real_hash_size = 256
Mon Jul 10 23:01:12 2017 us=402644   virtual_hash_size = 256
Mon Jul 10 23:01:12 2017 us=402667   client_connect_script = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=402690   learn_address_script = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=402718   client_disconnect_script = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=402744   client_config_dir = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=402767   ccd_exclusive = DISABLED
Mon Jul 10 23:01:12 2017 us=402790   tmp_dir = '/tmp'
Mon Jul 10 23:01:12 2017 us=402814   push_ifconfig_defined = DISABLED
Mon Jul 10 23:01:12 2017 us=402840   push_ifconfig_local = 0.0.0.0
Mon Jul 10 23:01:12 2017 us=402866   push_ifconfig_remote_netmask = 0.0.0.0
Mon Jul 10 23:01:12 2017 us=402889   enable_c2c = DISABLED
Mon Jul 10 23:01:12 2017 us=402912   duplicate_cn = DISABLED
Mon Jul 10 23:01:12 2017 us=402935   cf_max = 0
Mon Jul 10 23:01:12 2017 us=402959   cf_per = 0
Mon Jul 10 23:01:12 2017 us=402982   max_clients = 1024
Mon Jul 10 23:01:12 2017 us=403005   max_routes_per_client = 256
Mon Jul 10 23:01:12 2017 us=403029   auth_user_pass_verify_script = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=403052   auth_user_pass_verify_script_via_file = DISABLED
Mon Jul 10 23:01:12 2017 us=403076   ssl_flags = 0
Mon Jul 10 23:01:12 2017 us=403099   port_share_host = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=403122   port_share_port = 0
Mon Jul 10 23:01:12 2017 us=403145   client = DISABLED
Mon Jul 10 23:01:12 2017 us=403168   pull = DISABLED
Mon Jul 10 23:01:12 2017 us=403192   auth_user_pass_file = '[UNDEF]'
Mon Jul 10 23:01:12 2017 us=403221 OpenVPN 2.2.1 i486-linux-gnu [SSL] [LZO2] [EPOLL] [PKCS11] [eurephia] built on Jul  1 2011
Mon Jul 10 23:01:12 2017 us=403515 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Mon Jul 10 23:01:12 2017 us=415035 Diffie-Hellman initialized with 1024 bit key
Mon Jul 10 23:01:12 2017 us=415947 WARNING: file '/etc/openvpn/ta.key' is group or others accessible
Mon Jul 10 23:01:12 2017 us=415969 Control Channel Authentication: using '/etc/openvpn/ta.key' as a OpenVPN static key file
Mon Jul 10 23:01:12 2017 us=415997 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Jul 10 23:01:12 2017 us=416018 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Jul 10 23:01:12 2017 us=416066 TLS-Auth MTU parms [ L:1542 D:166 EF:66 EB:0 ET:0 EL:0 ]
Mon Jul 10 23:01:12 2017 us=416108 Socket Buffers: R=[112640->131072] S=[112640->131072]
Mon Jul 10 23:01:12 2017 us=416288 ROUTE default_gateway=192.168.254.1
Mon Jul 10 23:01:12 2017 us=418815 TUN/TAP device tun1 opened
Mon Jul 10 23:01:12 2017 us=418875 TUN/TAP TX queue length set to 100
Mon Jul 10 23:01:12 2017 us=418938 /sbin/ifconfig tun1 10.6.0.1 pointopoint 10.6.0.2 mtu 1500
Mon Jul 10 23:01:12 2017 us=420998 /sbin/route add -net 10.6.0.0 netmask 255.255.255.0 gw 10.6.0.2
Mon Jul 10 23:01:12 2017 us=422044 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Mon Jul 10 23:01:12 2017 us=423015 GID set to nobody
Mon Jul 10 23:01:12 2017 us=423119 UID set to nobody
Mon Jul 10 23:01:12 2017 us=423167 UDPv4 link local (bound): [undef]:1194
Mon Jul 10 23:01:12 2017 us=423189 UDPv4 link remote: [undef]
Mon Jul 10 23:01:12 2017 us=423218 MULTI: multi_init called, r=256 v=256
Mon Jul 10 23:01:12 2017 us=423341 IFCONFIG POOL: base=10.6.0.4 size=62
Mon Jul 10 23:01:12 2017 us=423380 IFCONFIG POOL LIST
Mon Jul 10 23:01:12 2017 us=423402 KSS1XMAC,10.6.0.4
Mon Jul 10 23:01:12 2017 us=423421 KSS1XR7PLUS,10.6.0.8
Mon Jul 10 23:01:12 2017 us=423464 Initialization Sequence Completed
Mon Jul 10 23:02:17 2017 us=75417 MULTI: multi_create_instance called
Mon Jul 10 23:02:17 2017 us=75528 192.168.254.210:61672 Re-using SSL/TLS context
Mon Jul 10 23:02:17 2017 us=75590 192.168.254.210:61672 LZO compression initialized
Mon Jul 10 23:02:17 2017 us=75925 192.168.254.210:61672 Control Channel MTU parms [ L:1542 D:166 EF:66 EB:0 ET:0 EL:0 ]
Mon Jul 10 23:02:17 2017 us=75961 192.168.254.210:61672 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
Mon Jul 10 23:02:17 2017 us=76047 192.168.254.210:61672 Local Options String: 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,keydir 0,cipher BF-CBC,auth SHA1,keysize 128,tls-auth,key-method 2,tls-server'
Mon Jul 10 23:02:17 2017 us=76076 192.168.254.210:61672 Expected Remote Options String: 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,keydir 1,cipher BF-CBC,auth SHA1,keysize 128,tls-auth,key-method 2,tls-client'
Mon Jul 10 23:02:17 2017 us=76127 192.168.254.210:61672 Local Options hash (VER=V4): '14168603'
Mon Jul 10 23:02:17 2017 us=76165 192.168.254.210:61672 Expected Remote Options hash (VER=V4): '504e774e'
Mon Jul 10 23:02:17 2017 us=76270 192.168.254.210:61672 UDPv4 READ [42] from 192.168.254.210:61672: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 pid=[ #1 ] [ ] pid=0 DATA len=0
Mon Jul 10 23:02:17 2017 us=76319 192.168.254.210:61672 TLS: Initial packet from 192.168.254.210:61672, sid=24b17bd5 06d8e1e3
Mon Jul 10 23:02:17 2017 us=76394 192.168.254.210:61672 UDPv4 WRITE [54] to 192.168.254.210:61672: P_CONTROL_HARD_RESET_SERVER_V2 kid=0 pid=[ #1 ] [ 0 ] pid=0 DATA len=0
Mon Jul 10 23:02:17 2017 us=77424 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #2 ] [ 0 ]
Mon Jul 10 23:02:17 2017 us=77841 192.168.254.210:61672 UDPv4 READ [287] from 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #3 ] [ ] pid=1 DATA len=245
Mon Jul 10 23:02:17 2017 us=94776 192.168.254.210:61672 UDPv4 WRITE [154] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #2 ] [ 1 ] pid=1 DATA len=100
Mon Jul 10 23:02:17 2017 us=94815 192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #3 ] [ ] pid=2 DATA len=100
Mon Jul 10 23:02:17 2017 us=94847 192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #4 ] [ ] pid=3 DATA len=100
Mon Jul 10 23:02:17 2017 us=94877 192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #5 ] [ ] pid=4 DATA len=100
Mon Jul 10 23:02:17 2017 us=95975 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #4 ] [ 1 ]
Mon Jul 10 23:02:17 2017 us=96045 192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #6 ] [ ] pid=5 DATA len=100
Mon Jul 10 23:02:17 2017 us=96374 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #5 ] [ 2 ]
Mon Jul 10 23:02:17 2017 us=96460 192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #7 ] [ ] pid=6 DATA len=100
Mon Jul 10 23:02:17 2017 us=96528 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #6 ] [ 3 ]
Mon Jul 10 23:02:17 2017 us=96556 192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #8 ] [ ] pid=7 DATA len=100
Mon Jul 10 23:02:17 2017 us=96582 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #7 ] [ 4 ]
Mon Jul 10 23:02:17 2017 us=96609 192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #9 ] [ ] pid=8 DATA len=100
Mon Jul 10 23:02:17 2017 us=97217 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #8 ] [ 5 ]
Mon Jul 10 23:02:17 2017 us=97283 192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #10 ] [ ] pid=9 DATA len=100
Mon Jul 10 23:02:17 2017 us=97614 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #9 ] [ 6 ]
Mon Jul 10 23:02:17 2017 us=97680 192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #11 ] [ ] pid=10 DATA len=100
Mon Jul 10 23:02:17 2017 us=97745 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #10 ] [ 7 ]
Mon Jul 10 23:02:17 2017 us=97790 192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #12 ] [ ] pid=11 DATA len=100
Mon Jul 10 23:02:17 2017 us=97817 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #11 ] [ 8 ]
Mon Jul 10 23:02:17 2017 us=97844 192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #13 ] [ ] pid=12 DATA len=100
Mon Jul 10 23:02:17 2017 us=102303 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #12 ] [ 9 ]
Mon Jul 10 23:02:17 2017 us=102371 192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #14 ] [ ] pid=13 DATA len=100
Mon Jul 10 23:02:17 2017 us=102697 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #13 ] [ 10 ]
Mon Jul 10 23:02:17 2017 us=102763 192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #15 ] [ ] pid=14 DATA len=100
Mon Jul 10 23:02:17 2017 us=102825 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #14 ] [ 11 ]
Mon Jul 10 23:02:17 2017 us=102873 192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #16 ] [ ] pid=15 DATA len=100
Mon Jul 10 23:02:17 2017 us=104088 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #15 ] [ 12 ]
Mon Jul 10 23:02:17 2017 us=104153 192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #17 ] [ ] pid=16 DATA len=100
Mon Jul 10 23:02:17 2017 us=104408 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #16 ] [ 13 ]
Mon Jul 10 23:02:17 2017 us=104483 192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #18 ] [ ] pid=17 DATA len=100
Mon Jul 10 23:02:17 2017 us=104546 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #17 ] [ 14 ]
Mon Jul 10 23:02:17 2017 us=104608 192.168.254.210:61672 UDPv4 WRITE [78] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #19 ] [ ] pid=18 DATA len=36
Mon Jul 10 23:02:17 2017 us=104666 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #18 ] [ 15 ]
Mon Jul 10 23:02:17 2017 us=105619 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #19 ] [ 16 ]
Mon Jul 10 23:02:17 2017 us=105936 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #20 ] [ 17 ]
Mon Jul 10 23:02:17 2017 us=123268 192.168.254.210:61672 UDPv4 READ [1172] from 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #21 ] [ 18 ] pid=2 DATA len=1118
Mon Jul 10 23:02:17 2017 us=123359 192.168.254.210:61672 UDPv4 WRITE [50] to 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #20 ] [ 2 ]
Mon Jul 10 23:02:17 2017 us=123704 192.168.254.210:61672 UDPv4 READ [1160] from 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #22 ] [ ] pid=3 DATA len=1118
Mon Jul 10 23:02:17 2017 us=124207 192.168.254.210:61672 VERIFY OK: depth=1, /C=US/ST=CA/L=SanFrancisco/O=Fort-Funston/OU=changeme/CN=changeme/name=changeme/emailAddress=mail@host.domain
Mon Jul 10 23:02:17 2017 us=124424 192.168.254.210:61672 VERIFY OK: depth=0, /C=US/ST=CA/L=SanFrancisco/O=Fort-Funston/OU=changeme/CN=KSS1XMAC/name=changeme/emailAddress=mail@host.domain
Mon Jul 10 23:02:17 2017 us=131772 192.168.254.210:61672 UDPv4 WRITE [50] to 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #21 ] [ 3 ]
Mon Jul 10 23:02:17 2017 us=131810 192.168.254.210:61672 UDPv4 READ [193] from 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #23 ] [ ] pid=4 DATA len=151
Mon Jul 10 23:02:17 2017 us=132056 192.168.254.210:61672 UDPv4 WRITE [113] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #22 ] [ 4 ] pid=19 DATA len=59
Mon Jul 10 23:02:17 2017 us=133231 192.168.254.210:61672 UDPv4 READ [432] from 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #24 ] [ 19 ] pid=5 DATA len=378
Mon Jul 10 23:02:17 2017 us=133499 192.168.254.210:61672 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
Mon Jul 10 23:02:17 2017 us=133513 192.168.254.210:61672 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Jul 10 23:02:17 2017 us=133563 192.168.254.210:61672 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
Mon Jul 10 23:02:17 2017 us=133575 192.168.254.210:61672 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
Mon Jul 10 23:02:17 2017 us=133607 192.168.254.210:61672 UDPv4 WRITE [154] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #23 ] [ 5 ] pid=20 DATA len=100
Mon Jul 10 23:02:17 2017 us=133635 192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #24 ] [ ] pid=21 DATA len=100
Mon Jul 10 23:02:17 2017 us=133660 192.168.254.210:61672 UDPv4 WRITE [124] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #25 ] [ ] pid=22 DATA len=82
Mon Jul 10 23:02:17 2017 us=134427 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #25 ] [ 20 ]
Mon Jul 10 23:02:17 2017 us=134779 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #26 ] [ 21 ]
Mon Jul 10 23:02:17 2017 us=137878 192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #27 ] [ 22 ]
Mon Jul 10 23:02:17 2017 us=137929 192.168.254.210:61672 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 1024 bit RSA
Mon Jul 10 23:02:17 2017 us=137974 192.168.254.210:61672 [KSS1XMAC] Peer Connection Initiated with 192.168.254.210:61672
Mon Jul 10 23:02:17 2017 us=138064 KSS1XMAC/192.168.254.210:61672 MULTI: Learn: 10.6.0.6 -> KSS1XMAC/192.168.254.210:61672
Mon Jul 10 23:02:17 2017 us=138078 KSS1XMAC/192.168.254.210:61672 MULTI: primary virtual IP for KSS1XMAC/192.168.254.210:61672: 10.6.0.6
Mon Jul 10 23:02:19 2017 us=669334 KSS1XMAC/192.168.254.210:61672 UDPv4 READ [132] from 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #28 ] [ ] pid=6 DATA len=90
Mon Jul 10 23:02:19 2017 us=669463 KSS1XMAC/192.168.254.210:61672 PUSH: Received control message: 'PUSH_REQUEST'
Mon Jul 10 23:02:19 2017 us=669529 KSS1XMAC/192.168.254.210:61672 SENT CONTROL [KSS1XMAC]: 'PUSH_REPLY,route 192.168.254.0 255.255.255.0,route 10.6.0.1,topology net30,ping 10,ping-restart 120,ifconfig 10.6.0.6 10.6.0.5' (status=1)
Mon Jul 10 23:02:19 2017 us=669574 KSS1XMAC/192.168.254.210:61672 UDPv4 WRITE [50] to 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #26 ] [ 6 ]
Mon Jul 10 23:02:19 2017 us=669639 KSS1XMAC/192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #27 ] [ ] pid=23 DATA len=100
Mon Jul 10 23:02:19 2017 us=669718 KSS1XMAC/192.168.254.210:61672 UDPv4 WRITE [142] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #28 ] [ ] pid=24 DATA len=100
Mon Jul 10 23:02:19 2017 us=669778 KSS1XMAC/192.168.254.210:61672 UDPv4 WRITE [44] to 192.168.254.210:61672: P_CONTROL_V1 kid=0 pid=[ #29 ] [ ] pid=25 DATA len=2
Mon Jul 10 23:02:19 2017 us=672640 KSS1XMAC/192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #29 ] [ 23 ]
Mon Jul 10 23:02:19 2017 us=673020 KSS1XMAC/192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #30 ] [ 24 ]
Mon Jul 10 23:02:22 2017 us=13067 KSS1XMAC/192.168.254.210:61672 UDPv4 READ [50] from 192.168.254.210:61672: P_ACK_V1 kid=0 pid=[ #31 ] [ 25 ]
Mon Jul 10 23:02:29 2017 us=205435 KSS1XMAC/192.168.254.210:61672 UDPv4 WRITE [53] to 192.168.254.210:61672: P_DATA_V1 kid=0 DATA len=52
Mon Jul 10 23:02:39 2017 us=400800 KSS1XMAC/192.168.254.210:61672 UDPv4 WRITE [53] to 192.168.254.210:61672: P_DATA_V1 kid=0 DATA len=52
Mon Jul 10 23:02:39 2017 us=401945 read UDPv4 [ECONNREFUSED]: Connection refused (code=111)
now.. i switch my connection on my client using my mobile device hotspot internet sharing ... and try to connect to the server (again changing the remote to the remote address)..

no log entries on the server...

will post the log entries on the client on a separate post (thru the actual client)...

by the way.. at this point.. this is the OPENVPN server's route table:

Code: Select all

Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
10.8.0.5        *               255.255.255.255 UH    0      0        0 tun2
10.6.1.2        *               255.255.255.255 UH    0      0        0 tun0
10.6.0.2        *               255.255.255.255 UH    0      0        0 tun1
192.168.100.0   10.8.0.5        255.255.255.0   UG    0      0        0 tun2
192.168.102.0   10.8.0.5        255.255.255.0   UG    0      0        0 tun2
10.6.1.0        10.6.1.2        255.255.255.0   UG    0      0        0 tun0
10.6.0.0        10.6.0.2        255.255.255.0   UG    0      0        0 tun1
10.8.0.0        10.8.0.5        255.255.255.0   UG    0      0        0 tun2
192.168.254.0   *               255.255.255.0   U     0      0        0 eth0
link-local      *               255.255.0.0     U     1000   0        0 eth0
default         u1010router.loc 0.0.0.0         UG    100    0        0 eth0
OPENVPN iptables filter:

Code: Select all

Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         
OPENVPN iptables nat:

Code: Select all

Chain PREROUTING (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain POSTROUTING (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         
on the router... this is the route table:

Code: Select all

Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
default         192.168.1.1     0.0.0.0         UG    0      0        0 enp2s0
10.6.0.0        192.168.254.254 255.255.255.0   UG    0      0        0 enp1s0
10.6.1.0        192.168.254.254 255.255.255.0   UG    0      0        0 enp1s0
10.8.0.0        10.8.0.5        255.255.255.0   UG    0      0        0 tun2
10.8.0.5        *               255.255.255.255 UH    0      0        0 tun2
link-local      *               255.255.0.0     U     1000   0        0 enp1s0
192.168.1.0     *               255.255.255.0   U     0      0        0 enp2s0
192.168.100.0   10.8.0.5        255.255.255.0   UG    0      0        0 tun2
192.168.102.0   10.8.0.5        255.255.255.0   UG    0      0        0 tun2
192.168.254.0   *               255.255.255.0   U     0      0        0 enp1s0
iptables filter

Code: Select all

Chain INPUT (policy ACCEPT 586 packets, 63579 bytes)
 pkts bytes target     prot opt in     out     source               destination         
  184 17963 ACCEPT     all  --  lo     *       0.0.0.0/0            0.0.0.0/0           
    0     0 ACCEPT     all  --  tun+   *       0.0.0.0/0            0.0.0.0/0           
 1685 1136K ACCEPT     all  --  enp2s0 *       0.0.0.0/0            0.0.0.0/0            ctstate RELATED,ESTABLISHED
  791  296K ACCEPT     all  --  enp1s0 *       0.0.0.0/0            0.0.0.0/0            ctstate RELATED,ESTABLISHED
    0     0 SSH_ROUTER  tcp  --  *      *       0.0.0.0/0            0.0.0.0/0            tcp dpt:2222

Chain FORWARD (policy ACCEPT 1614 packets, 114K bytes)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 ACCEPT     all  --  tun+   *       0.0.0.0/0            0.0.0.0/0           
    0     0 ACCEPT     all  --  tun+   enp2s0  0.0.0.0/0            0.0.0.0/0            state RELATED,ESTABLISHED
    0     0 ACCEPT     all  --  enp2s0 tun+    0.0.0.0/0            0.0.0.0/0            state RELATED,ESTABLISHED
    0     0 ACCEPT     all  --  tun+   enp1s0  0.0.0.0/0            0.0.0.0/0            state RELATED,ESTABLISHED
    0     0 ACCEPT     all  --  enp1s0 tun+    0.0.0.0/0            0.0.0.0/0            state RELATED,ESTABLISHED
 2246  233K ACCEPT     all  --  enp1s0 enp2s0  0.0.0.0/0            0.0.0.0/0           
 2055  878K ACCEPT     all  --  enp2s0 enp1s0  0.0.0.0/0            0.0.0.0/0            ctstate RELATED,ESTABLISHED

Chain OUTPUT (policy ACCEPT 3277 packets, 336K bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain SSH_ROUTER (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 ACCEPT     all  --  *      *       192.168.254.0/24     0.0.0.0/0           
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0
iptables nat

Code: Select all

Chain PREROUTING (policy ACCEPT 700 packets, 57835 bytes)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 DNAT       udp  --  enp2s0 *       0.0.0.0/0            0.0.0.0/0            udp dpt:1194 to:192.168.254.254
    0     0 DNAT       udp  --  enp2s0 *       0.0.0.0/0            0.0.0.0/0            udp dpt:1195 to:192.168.254.254

Chain INPUT (policy ACCEPT 383 packets, 26039 bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain OUTPUT (policy ACCEPT 382 packets, 26570 bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain POSTROUTING (policy ACCEPT 514 packets, 34986 bytes)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 SNAT       udp  --  *      enp1s0  0.0.0.0/0            192.168.254.254      udp dpt:1194 to:192.168.254.1
    0     0 SNAT       udp  --  *      enp1s0  0.0.0.0/0            192.168.254.254      udp dpt:1195 to:192.168.254.1
  185 23380 MASQUERADE  all  --  *      enp2s0  192.168.254.0/24     0.0.0.0/0           
    0     0 MASQUERADE  all  --  *      enp2s0  10.6.0.0/24          0.0.0.0/0           
    0     0 MASQUERADE  all  --  *      enp2s0  10.6.1.0/24          0.0.0.0/0           
I did some reading on the way home... and I thought I'd try something out... but.. still can't access the separate OPENVPN server machine through the router if I am connecting from WAN.

wowiesy
OpenVPN User
Posts: 25
Joined: Mon Jul 10, 2017 6:33 am

Re: New UBUNTU server 16.04: Openvpn routing and firewall setup -> HELP!

Post by wowiesy » Mon Jul 10, 2017 3:20 pm

and here is the logs from the MAC openvpn client, when trying to connect from the WAN:

Code: Select all

*Tunnelblick: OS X 10.11.5; Tunnelblick 3.7.1b (build 4813); prior version 3.7.1a (build 4812); Admin user
git commit ea4b9e30939b4dfd3b69a71f62e91625fa8dd97f


Configuration U1010

"Sanitized" condensed configuration file for /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk:

client
dev tun
proto udp
remote u1010.duckdns.org 1194
resolv-retry infinite
nobind
persist-key
persist-tun
ca ca.crt
cert KSS1XMAC.crt
key KSS1XMAC.key
tls-auth ta.key 1
comp-lzo
verb 5


================================================================================

Non-Apple kexts that are loaded:

Index Refs Address            Size       Wired      Name (Version) UUID <Linked Against>
   24    0 0xffffff7f81277000 0x18000    0x18000    com.rim.driver.BlackBerryUSBDriverInt (0.0.74) 18378BE7-8E39-EE32-58BF-0DD52AA71357 <23 22 21 20 18 5 4 3 1>
  137    3 0xffffff7f82dac000 0x60000    0x60000    org.virtualbox.kext.VBoxDrv (5.0.10) 23DD0853-7210-3AF2-85FA-1C7FF8F7D1BF <7 5 4 3 1>
  143    0 0xffffff7f82e0c000 0x8000     0x8000     org.virtualbox.kext.VBoxUSB (5.0.10) C5D33477-F93D-36AD-8748-1EB1105FB93A <142 137 18 7 5 4 3 1>
  144    0 0xffffff7f82e14000 0x5000     0x5000     org.virtualbox.kext.VBoxNetFlt (5.0.10) E5ABC825-5396-34A7-9B63-3A38E9142EEC <137 7 5 4 3 1>
  145    0 0xffffff7f82e19000 0x6000     0x6000     org.virtualbox.kext.VBoxNetAdp (5.0.10) BEFC91DC-800F-3F16-8388-50584243FB30 <137 5 4 1>

================================================================================

There are no unusual files in U1010.tblk

================================================================================

Configuration preferences:

-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 1
-lastConnectionSucceeded = 0
-tunnelDownSoundName = None
-tunnelUpSoundName = None

================================================================================

Wildcard preferences:

-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 1

================================================================================

Program preferences:

skipWarningAboutPlacingIconNearTheSpotlightIcon = 1
placeIconInStandardPositionInStatusBar = 0
launchAtNextLogin = 1
notOKToCheckThatIPAddressDidNotChangeAfterConnection = 1
askedUserIfOKToCheckThatIPAddressDidNotChangeAfterConnection = 1
tunnelblickVersionHistory = (
    "3.7.1b (build 4813)",
    "3.7.1a (build 4812)",
    "3.7.1 (build 4811)",
    "3.7.0 (build 4790)",
    "3.6.10 (build 4760)",
    "3.6.9 (build 4685)",
    "3.6.8 (build 4625)",
    "3.6.3 (build 4560)",
    "3.4.4 (build 4055.4236)",
    "3.6.0a (build 4543.4546)"
)
lastLaunchTime = 521155278.018634
showConnectedDurations = 1
lastLanguageAtLaunchWasRTL = 0
connectionWindowDisplayCriteria = showWhenConnecting
maxLogDisplaySize = 102400
lastConnectedDisplayName = U1010
keyboardShortcutIndex = 1
updateCheckAutomatically = 1
updateSendProfileInfo = 1
NSWindow Frame ConnectingWindow = 445 449 389 187 0 0 1280 777 
NSWindow Frame SUStatusFrame = 816 437 400 129 0 0 1280 777 
NSWindow Frame SUUpdateAlert = 330 295 620 392 0 0 1280 777 
detailsWindowFrameVersion = 4813
detailsWindowFrame = {{180, 238}, {920, 468}}
detailsWindowLeftFrame = {{0, 0}, {165, 350}}
detailsWindowViewIndex = 0
detailsWindowConfigurationsTabIdentifier = log
leftNavSelectedDisplayName = U1010
AdvancedWindowTabIdentifier = connectingAndDisconnecting
haveDealtWithSparkle1dot5b6 = 1
haveDealtWithOldTunTapPreferences = 1
haveDealtWithOldLoginItem = 1
SUEnableAutomaticChecks = 1
SUFeedURL = https://www.tunnelblick.net/appcast-s.rss
SUScheduledCheckInterval = 86400
SUSendProfileInfo = 1
SULastCheckTime = 2017-07-07 21:21:23 +0000
SULastProfileSubmissionDate = 2017-07-07 12:42:24 +0000
SUHasLaunchedBefore = 1
WebKitDefaultFontSize = 11
WebKitStandardFont = .AppleSystemUIFont
tunnelblickdHash = 982f7a7b2b98739801aa88b72712259b30dea31dbe8f2662db447888ff2ff295
tunnelblickdPlistHash = ce400d395d1801b003398461b5420021f4d591822783a04b79b2f43956d28620

================================================================================

Tunnelblick Log:

2017-07-10 23:07:18 OpenVPN 2.3.17 x86_64-apple-darwin [SSL (OpenSSL)] [LZO] [PKCS11] [MH] [IPv6] built on Jun 21 2017
2017-07-10 23:07:18 library versions: OpenSSL 1.0.2k  26 Jan 2017, LZO 2.09
2017-07-10 23:07:18 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:1337
2017-07-10 23:07:18 Need hold release from management interface, waiting...
*Tunnelblick: OS X 10.11.5; Tunnelblick 3.7.1b (build 4813); prior version 3.7.1a (build 4812)
2017-07-10 23:07:18 *Tunnelblick: Attempting connection with U1010 using shadow copy; Set nameserver = 769; monitoring connection
2017-07-10 23:07:18 *Tunnelblick: openvpnstart start U1010.tblk 1337 769 0 1 0 1065264 -ptADGNWradsgnw 2.3.17-openssl-1.0.2k
2017-07-10 23:07:19 *Tunnelblick: openvpnstart log:
     OpenVPN started successfully. Command used to start OpenVPN (one argument per displayed line):
     
          /Applications/Tunnelblick.app/Contents/Resources/openvpn/openvpn-2.3.17-openssl-1.0.2k/openvpn
          --daemon
          --log
          /Library/Application Support/Tunnelblick/Logs/-SUsers-Skss1x-SLibrary-SApplication Support-STunnelblick-SConfigurations-SU1010.tblk-SContents-SResources-Sconfig.ovpn.769_0_1_0_1065264.1337.openvpn.log
          --cd
          /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
          --verb
          3
          --config
          /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
          --verb
          3
          --cd
          /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
          --management
          127.0.0.1
          1337
          --management-query-passwords
          --management-hold
          --script-security
          2
          --up
          /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw
          --down
          /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw

2017-07-10 23:07:18 *Tunnelblick: openvpnstart starting OpenVPN
2017-07-10 23:07:19 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:1337
2017-07-10 23:07:19 MANAGEMENT: CMD 'pid'
2017-07-10 23:07:19 MANAGEMENT: CMD 'state on'
2017-07-10 23:07:19 MANAGEMENT: CMD 'state'
2017-07-10 23:07:19 MANAGEMENT: CMD 'bytecount 1'
2017-07-10 23:07:19 MANAGEMENT: CMD 'hold release'
2017-07-10 23:07:19 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:07:19 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:07:19 Control Channel Authentication: using 'ta.key' as a OpenVPN static key file
2017-07-10 23:07:19 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
2017-07-10 23:07:19 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
2017-07-10 23:07:19 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:07:19 MANAGEMENT: >STATE:1499699239,RESOLVE,,,
2017-07-10 23:07:19 *Tunnelblick: Established communication with OpenVPN
2017-07-10 23:07:20 UDPv4 link local: [undef]
2017-07-10 23:07:20 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:07:20 MANAGEMENT: >STATE:1499699240,WAIT,,,
2017-07-10 23:08:20 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:08:20 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:08:20 TLS Error: TLS handshake failed
2017-07-10 23:08:20 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:08:20 MANAGEMENT: >STATE:1499699300,RECONNECTING,tls-error,,
2017-07-10 23:08:20 MANAGEMENT: CMD 'hold release'
2017-07-10 23:08:20 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:08:20 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:08:20 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:08:20 MANAGEMENT: >STATE:1499699300,RESOLVE,,,
2017-07-10 23:08:20 UDPv4 link local: [undef]
2017-07-10 23:08:20 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:08:20 MANAGEMENT: >STATE:1499699300,WAIT,,,
2017-07-10 23:09:20 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:09:20 TLS Error: TLS handshake failed
2017-07-10 23:09:20 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:09:20 MANAGEMENT: >STATE:1499699360,RECONNECTING,tls-error,,
2017-07-10 23:09:21 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:09:21 MANAGEMENT: CMD 'hold release'
2017-07-10 23:09:21 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:09:21 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:09:21 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:09:21 MANAGEMENT: >STATE:1499699361,RESOLVE,,,
2017-07-10 23:09:21 UDPv4 link local: [undef]
2017-07-10 23:09:21 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:09:21 MANAGEMENT: >STATE:1499699361,WAIT,,,
2017-07-10 23:10:21 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:10:21 TLS Error: TLS handshake failed
2017-07-10 23:10:21 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:10:21 MANAGEMENT: >STATE:1499699421,RECONNECTING,tls-error,,
2017-07-10 23:10:21 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:10:21 MANAGEMENT: CMD 'hold release'
2017-07-10 23:10:21 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:10:21 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:10:21 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:10:21 MANAGEMENT: >STATE:1499699421,RESOLVE,,,
2017-07-10 23:10:21 UDPv4 link local: [undef]
2017-07-10 23:10:21 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:10:21 MANAGEMENT: >STATE:1499699421,WAIT,,,
2017-07-10 23:11:21 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:11:21 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:11:21 TLS Error: TLS handshake failed
2017-07-10 23:11:21 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:11:21 MANAGEMENT: >STATE:1499699481,RECONNECTING,tls-error,,
2017-07-10 23:11:21 MANAGEMENT: CMD 'hold release'
2017-07-10 23:11:21 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:11:21 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:11:21 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:11:21 MANAGEMENT: >STATE:1499699481,RESOLVE,,,
2017-07-10 23:11:21 UDPv4 link local: [undef]
2017-07-10 23:11:21 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:11:21 MANAGEMENT: >STATE:1499699481,WAIT,,,
2017-07-10 23:12:21 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:12:21 TLS Error: TLS handshake failed
2017-07-10 23:12:21 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:12:21 MANAGEMENT: >STATE:1499699541,RECONNECTING,tls-error,,
2017-07-10 23:12:21 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:12:21 MANAGEMENT: CMD 'hold release'
2017-07-10 23:12:21 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:12:21 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:12:21 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:12:21 MANAGEMENT: >STATE:1499699541,RESOLVE,,,
2017-07-10 23:12:22 UDPv4 link local: [undef]
2017-07-10 23:12:22 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:12:22 MANAGEMENT: >STATE:1499699542,WAIT,,,
2017-07-10 23:13:22 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:13:22 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:13:22 TLS Error: TLS handshake failed
2017-07-10 23:13:22 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:13:22 MANAGEMENT: >STATE:1499699602,RECONNECTING,tls-error,,
2017-07-10 23:13:22 MANAGEMENT: CMD 'hold release'
2017-07-10 23:13:22 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:13:22 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:13:22 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:13:22 MANAGEMENT: >STATE:1499699602,RESOLVE,,,
2017-07-10 23:13:22 UDPv4 link local: [undef]
2017-07-10 23:13:22 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:13:22 MANAGEMENT: >STATE:1499699602,WAIT,,,
2017-07-10 23:14:23 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:14:23 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:14:23 TLS Error: TLS handshake failed
2017-07-10 23:14:23 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:14:23 MANAGEMENT: >STATE:1499699663,RECONNECTING,tls-error,,
2017-07-10 23:14:23 MANAGEMENT: CMD 'hold release'
2017-07-10 23:14:23 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:14:23 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:14:23 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:14:23 MANAGEMENT: >STATE:1499699663,RESOLVE,,,
2017-07-10 23:14:23 UDPv4 link local: [undef]
2017-07-10 23:14:23 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:14:23 MANAGEMENT: >STATE:1499699663,WAIT,,,
2017-07-10 23:15:23 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:15:23 TLS Error: TLS handshake failed
2017-07-10 23:15:23 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:15:23 MANAGEMENT: >STATE:1499699723,RECONNECTING,tls-error,,
2017-07-10 23:15:23 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:15:23 MANAGEMENT: CMD 'hold release'
2017-07-10 23:15:23 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:15:23 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:15:23 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:15:23 MANAGEMENT: >STATE:1499699723,RESOLVE,,,
2017-07-10 23:15:23 UDPv4 link local: [undef]
2017-07-10 23:15:23 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:15:23 MANAGEMENT: >STATE:1499699723,WAIT,,,
2017-07-10 23:16:23 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:16:23 TLS Error: TLS handshake failed
2017-07-10 23:16:23 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:16:23 MANAGEMENT: >STATE:1499699783,RECONNECTING,tls-error,,
2017-07-10 23:16:23 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:16:23 MANAGEMENT: CMD 'hold release'
2017-07-10 23:16:23 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:16:23 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:16:23 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:16:23 MANAGEMENT: >STATE:1499699783,RESOLVE,,,
2017-07-10 23:16:23 UDPv4 link local: [undef]
2017-07-10 23:16:23 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:16:23 MANAGEMENT: >STATE:1499699783,WAIT,,,
2017-07-10 23:16:34 *Tunnelblick: Disconnecting; notification window disconnect button pressed
2017-07-10 23:16:34 *Tunnelblick: No 'pre-disconnect.sh' script to execute
2017-07-10 23:16:34 *Tunnelblick: Disconnecting using 'kill'
2017-07-10 23:16:34 event_wait : Interrupted system call (code=4)
2017-07-10 23:16:34 SIGTERM[hard,] received, process exiting
2017-07-10 23:16:34 MANAGEMENT: >STATE:1499699794,EXITING,SIGTERM,,
2017-07-10 23:16:35 *Tunnelblick: No 'post-disconnect.sh' script to execute
2017-07-10 23:16:35 *Tunnelblick: Expected disconnection occurred.

================================================================================

"Sanitized" full configuration file

##############################################
# Sample client-side OpenVPN 2.0 config file #
# for connecting to multi-client server.     #
#                                            #
# This configuration can be used by multiple #
# clients, however each client should have   #
# its own cert and key files.                #
#                                            #
# On Windows, you might want to rename this  #
# file so it has a .ovpn extension           #
##############################################

# Specify that we are a client and that we
# will be pulling certain config file directives
# from the server.
client

# Use the same setting as you are using on
# the server.
# On most systems, the VPN will not function
# unless you partially or fully disable
# the firewall for the TUN/TAP interface.
;dev tap
dev tun

# Windows needs the TAP-Win32 adapter name
# from the Network Connections panel
# if you have more than one.  On XP SP2,
# you may need to disable the firewall
# for the TAP adapter.
;dev-node MyTap

# Are we connecting to a TCP or
# UDP server?  Use the same setting as
# on the server.
;proto tcp
proto udp

# The hostname/IP and port of the server.
# You can have multiple remote entries
# to load balance between the servers.
;remote 192.168.254.254 1194
;remote u1010.dyndns-ip.com 1194
;remote U1010.no-ip.org 1194
remote u1010.duckdns.org 1194

# Choose a random host from the remote
# list for load-balancing.  Otherwise
# try hosts in the order specified.
;remote-random

# Keep trying indefinitely to resolve the
# host name of the OpenVPN server.  Very useful
# on machines which are not permanently connected
# to the internet such as laptops.
resolv-retry infinite

# Most clients don't need to bind to
# a specific local port number.
nobind

# Downgrade privileges after initialization (non-Windows only)
;user nobody
;group nobody

# Try to preserve some state across restarts.
persist-key
persist-tun

# If you are connecting through an
# HTTP proxy to reach the actual OpenVPN
# server, put the proxy server/IP and
# port number here.  See the man page
# if your proxy server requires
# authentication.
;http-proxy-retry # retry on connection failures
;http-proxy [proxy server] [proxy port #]

# Wireless networks often produce a lot
# of duplicate packets.  Set this flag
# to silence duplicate packet warnings.
;mute-replay-warnings

# SSL/TLS parms.
# See the server config file for more
# description.  It's best to use
# a separate .crt/.key file pair
# for each client.  A single ca
# file can be used for all clients.
# ca /Users/kss1x/Library/openvpn/ca.crt
# cert /Users/kss1x/Library/openvpn/KSS1XMAC.crt 
# key /Users/kss1x/Library/openvpn/KSS1XMAC.key 

ca ca.crt
cert KSS1XMAC.crt
key KSS1XMAC.key

# Verify server certificate by checking
# that the certicate has the nsCertType
# field set to "server".  This is an
# important precaution to protect against
# a potential attack discussed here:
#  http://openvpn.net/howto.html#mitm
#
# To use this feature, you will need to generate
# your server certificates with the nsCertType
# field set to "server".  The build-key-server
# script in the easy-rsa folder will do this.
;ns-cert-type server

# If a tls-auth key is used on the server
# then every client must also have the key.
tls-auth ta.key 1

# Select a cryptographic cipher.
# If the cipher option is used on the server
# then you must also specify it here.
;cipher x

# Enable compression on the VPN link.
# Don't enable this unless it is also
# enabled in the server config file.
comp-lzo

# Set log file verbosity.
verb 5

# Silence repeating messages
;mute 20



================================================================================

ifconfig output:

lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
	options=3<RXCSUM,TXCSUM>
	inet6 ::1 prefixlen 128 
	inet 127.0.0.1 netmask 0xff000000 
	inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1 
	nd6 options=1<PERFORMNUD>
gif0: flags=8010<POINTOPOINT,MULTICAST> mtu 1280
stf0: flags=0<> mtu 1280
en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
	options=27<RXCSUM,TXCSUM,VLAN_MTU,TSO4>
	ether 34:15:9e:23:1e:80 
	nd6 options=1<PERFORMNUD>
	media: autoselect
	status: inactive
en1: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
	ether 00:26:bb:0a:71:92 
	inet6 fe80::226:bbff:fe0a:7192%en1 prefixlen 64 scopeid 0x5 
	inet 192.168.43.99 netmask 0xffffff00 broadcast 192.168.43.255
	nd6 options=1<PERFORMNUD>
	media: autoselect
	status: active
fw0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 4078
	lladdr 34:15:9e:ff:fe:23:1e:80 
	nd6 options=1<PERFORMNUD>
	media: autoselect <full-duplex>
	status: inactive
p2p0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 2304
	ether 02:26:bb:0a:71:92 
	media: autoselect
	status: inactive

================================================================================

Console Log:

2017-07-10 18:28:09 kernel[0] PM response took 282 ms (568, Tunnelblick)
2017-07-10 21:44:47 tunnelblickd[2698] Status = 252 from tunnelblick-helper command 'compareShadowCopy U1010'
2017-07-10 21:44:47 Tunnelblick[568] tunnelblickd status from compareShadowCopy: 252
2017-07-10 21:44:54 Tunnelblick[568] Tunnelblick needs to perform an action that requires administrator authorization.
2017-07-10 21:44:54 Tunnelblick[568] Beginning installation or repair
2017-07-10 21:44:54 authexec[2709] executing /Applications/Tunnelblick.app/Contents/Resources/installer
2017-07-10 21:44:54 Tunnelblick[568] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-07-10 21:44:54. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                            /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                       Copied /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                           to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished without error
2017-07-10 21:44:54 Tunnelblick[568] Created or updated secure (shadow) copy of configuration file /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
2017-07-10 22:04:04 tunnelblickd[2888] Status = 252 from tunnelblick-helper command 'compareShadowCopy U1010'
2017-07-10 22:04:04 Tunnelblick[568] tunnelblickd status from compareShadowCopy: 252
2017-07-10 22:04:10 Tunnelblick[568] Tunnelblick needs to perform an action that requires administrator authorization.
2017-07-10 22:04:10 Tunnelblick[568] Beginning installation or repair
2017-07-10 22:04:10 authexec[2903] executing /Applications/Tunnelblick.app/Contents/Resources/installer
2017-07-10 22:04:10 Tunnelblick[568] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-07-10 22:04:10. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                            /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                       Copied /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                           to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished without error
2017-07-10 22:04:10 Tunnelblick[568] Created or updated secure (shadow) copy of configuration file /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
2017-07-10 22:05:09 tunnelblickd[2888] Status = 252 from tunnelblick-helper command 'compareShadowCopy U1010'
2017-07-10 22:05:09 Tunnelblick[568] tunnelblickd status from compareShadowCopy: 252
2017-07-10 22:05:14 Tunnelblick[568] Tunnelblick needs to perform an action that requires administrator authorization.
2017-07-10 22:05:14 Tunnelblick[568] Beginning installation or repair
2017-07-10 22:05:14 authexec[2989] executing /Applications/Tunnelblick.app/Contents/Resources/installer
2017-07-10 22:05:14 Tunnelblick[568] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-07-10 22:05:14. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                            /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                       Copied /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                           to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished without error
2017-07-10 22:05:14 Tunnelblick[568] Created or updated secure (shadow) copy of configuration file /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
2017-07-10 22:47:25 tunnelblickd[3158] Status = 252 from tunnelblick-helper command 'compareShadowCopy U1010'
2017-07-10 22:47:25 Tunnelblick[568] tunnelblickd status from compareShadowCopy: 252
2017-07-10 22:47:33 Tunnelblick[568] Tunnelblick needs to perform an action that requires administrator authorization.
2017-07-10 22:47:33 Tunnelblick[568] Beginning installation or repair
2017-07-10 22:47:33 authexec[3173] executing /Applications/Tunnelblick.app/Contents/Resources/installer
2017-07-10 22:47:33 Tunnelblick[568] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-07-10 22:47:33. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                            /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                       Copied /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                           to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished without error
2017-07-10 22:47:33 Tunnelblick[568] Created or updated secure (shadow) copy of configuration file /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
2017-07-10 22:53:55 tunnelblickd[3270] Status = 252 from tunnelblick-helper command 'compareShadowCopy U1010'
2017-07-10 22:53:55 Tunnelblick[568] tunnelblickd status from compareShadowCopy: 252
2017-07-10 22:54:01 Tunnelblick[568] Tunnelblick needs to perform an action that requires administrator authorization.
2017-07-10 22:54:01 Tunnelblick[568] Beginning installation or repair
2017-07-10 22:54:01 authexec[3276] executing /Applications/Tunnelblick.app/Contents/Resources/installer
2017-07-10 22:54:01 Tunnelblick[568] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-07-10 22:54:01. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                            /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                       Copied /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                           to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished without error
2017-07-10 22:54:01 Tunnelblick[568] Created or updated secure (shadow) copy of configuration file /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
2017-07-10 22:54:02 tunnelblickd[3270] Status = 251 from tunnelblick-helper command 'start U1010.tblk 1337 769 0 1 0 1065264 -ptADGNWradsgnw 2.3.17-openssl-1.0.2k'
2017-07-10 22:54:02 Tunnelblick[568] tunnelblickd status from start: 251
2017-07-10 22:54:26 tunnelblickd[3270] Status = 252 from tunnelblick-helper command 'compareShadowCopy U1010'
2017-07-10 22:54:26 Tunnelblick[568] tunnelblickd status from compareShadowCopy: 252
2017-07-10 22:54:32 Tunnelblick[568] Tunnelblick needs to perform an action that requires administrator authorization.
2017-07-10 22:54:32 Tunnelblick[568] Beginning installation or repair
2017-07-10 22:54:32 authexec[3288] executing /Applications/Tunnelblick.app/Contents/Resources/installer
2017-07-10 22:54:32 Tunnelblick[568] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-07-10 22:54:32. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                            /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                       Copied /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                           to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished without error
2017-07-10 22:54:32 Tunnelblick[568] Created or updated secure (shadow) copy of configuration file /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
2017-07-10 23:02:09 tunnelblickd[3328] Status = 252 from tunnelblick-helper command 'compareShadowCopy U1010'
2017-07-10 23:02:09 Tunnelblick[568] tunnelblickd status from compareShadowCopy: 252
2017-07-10 23:02:15 Tunnelblick[568] Tunnelblick needs to perform an action that requires administrator authorization.
2017-07-10 23:02:15 Tunnelblick[568] Beginning installation or repair
2017-07-10 23:02:15 authexec[3339] executing /Applications/Tunnelblick.app/Contents/Resources/installer
2017-07-10 23:02:15 Tunnelblick[568] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-07-10 23:02:15. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                            /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                       Copied /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                           to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished without error
2017-07-10 23:02:15 Tunnelblick[568] Created or updated secure (shadow) copy of configuration file /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
2017-07-10 23:07:11 tunnelblickd[3432] Status = 252 from tunnelblick-helper command 'compareShadowCopy U1010'
2017-07-10 23:07:11 Tunnelblick[568] tunnelblickd status from compareShadowCopy: 252
2017-07-10 23:07:18 Tunnelblick[568] Tunnelblick needs to perform an action that requires administrator authorization.
2017-07-10 23:07:18 Tunnelblick[568] Beginning installation or repair
2017-07-10 23:07:18 authexec[3438] executing /Applications/Tunnelblick.app/Contents/Resources/installer
2017-07-10 23:07:18 Tunnelblick[568] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-07-10 23:07:18. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                            /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                       Copied /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                           to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished without error
2017-07-10 23:07:18 Tunnelblick[568] Created or updated secure (shadow) copy of configuration file /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk


wowiesy
OpenVPN User
Posts: 25
Joined: Mon Jul 10, 2017 6:33 am

Re: New UBUNTU server 16.04: Openvpn routing and firewall setup -> HELP!

Post by wowiesy » Mon Jul 10, 2017 3:26 pm

and here is the Mac client logs... when I tried connecting to the OPENVPN server thru WAN (multiple times):

Code: Select all

2017-07-10 23:07:18 *Tunnelblick: openvpnstart starting OpenVPN
2017-07-10 23:07:19 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:1337
2017-07-10 23:07:19 MANAGEMENT: CMD 'pid'
2017-07-10 23:07:19 MANAGEMENT: CMD 'state on'
2017-07-10 23:07:19 MANAGEMENT: CMD 'state'
2017-07-10 23:07:19 MANAGEMENT: CMD 'bytecount 1'
2017-07-10 23:07:19 MANAGEMENT: CMD 'hold release'
2017-07-10 23:07:19 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:07:19 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:07:19 Control Channel Authentication: using 'ta.key' as a OpenVPN static key file
2017-07-10 23:07:19 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
2017-07-10 23:07:19 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
2017-07-10 23:07:19 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:07:19 MANAGEMENT: >STATE:1499699239,RESOLVE,,,
2017-07-10 23:07:19 *Tunnelblick: Established communication with OpenVPN
2017-07-10 23:07:20 UDPv4 link local: [undef]
2017-07-10 23:07:20 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:07:20 MANAGEMENT: >STATE:1499699240,WAIT,,,
2017-07-10 23:08:20 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:08:20 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:08:20 TLS Error: TLS handshake failed
2017-07-10 23:08:20 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:08:20 MANAGEMENT: >STATE:1499699300,RECONNECTING,tls-error,,
2017-07-10 23:08:20 MANAGEMENT: CMD 'hold release'
2017-07-10 23:08:20 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:08:20 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:08:20 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:08:20 MANAGEMENT: >STATE:1499699300,RESOLVE,,,
2017-07-10 23:08:20 UDPv4 link local: [undef]
2017-07-10 23:08:20 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:08:20 MANAGEMENT: >STATE:1499699300,WAIT,,,
2017-07-10 23:09:20 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:09:20 TLS Error: TLS handshake failed
2017-07-10 23:09:20 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:09:20 MANAGEMENT: >STATE:1499699360,RECONNECTING,tls-error,,
2017-07-10 23:09:21 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:09:21 MANAGEMENT: CMD 'hold release'
2017-07-10 23:09:21 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:09:21 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:09:21 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:09:21 MANAGEMENT: >STATE:1499699361,RESOLVE,,,
2017-07-10 23:09:21 UDPv4 link local: [undef]
2017-07-10 23:09:21 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:09:21 MANAGEMENT: >STATE:1499699361,WAIT,,,
2017-07-10 23:10:21 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:10:21 TLS Error: TLS handshake failed
2017-07-10 23:10:21 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:10:21 MANAGEMENT: >STATE:1499699421,RECONNECTING,tls-error,,
2017-07-10 23:10:21 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:10:21 MANAGEMENT: CMD 'hold release'
2017-07-10 23:10:21 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:10:21 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:10:21 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:10:21 MANAGEMENT: >STATE:1499699421,RESOLVE,,,
2017-07-10 23:10:21 UDPv4 link local: [undef]
2017-07-10 23:10:21 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:10:21 MANAGEMENT: >STATE:1499699421,WAIT,,,
2017-07-10 23:11:21 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:11:21 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:11:21 TLS Error: TLS handshake failed
2017-07-10 23:11:21 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:11:21 MANAGEMENT: >STATE:1499699481,RECONNECTING,tls-error,,
2017-07-10 23:11:21 MANAGEMENT: CMD 'hold release'
2017-07-10 23:11:21 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:11:21 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:11:21 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:11:21 MANAGEMENT: >STATE:1499699481,RESOLVE,,,
2017-07-10 23:11:21 UDPv4 link local: [undef]
2017-07-10 23:11:21 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:11:21 MANAGEMENT: >STATE:1499699481,WAIT,,,
2017-07-10 23:12:21 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:12:21 TLS Error: TLS handshake failed
2017-07-10 23:12:21 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:12:21 MANAGEMENT: >STATE:1499699541,RECONNECTING,tls-error,,
2017-07-10 23:12:21 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:12:21 MANAGEMENT: CMD 'hold release'
2017-07-10 23:12:21 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:12:21 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:12:21 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:12:21 MANAGEMENT: >STATE:1499699541,RESOLVE,,,
2017-07-10 23:12:22 UDPv4 link local: [undef]
2017-07-10 23:12:22 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:12:22 MANAGEMENT: >STATE:1499699542,WAIT,,,
2017-07-10 23:13:22 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:13:22 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:13:22 TLS Error: TLS handshake failed
2017-07-10 23:13:22 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:13:22 MANAGEMENT: >STATE:1499699602,RECONNECTING,tls-error,,
2017-07-10 23:13:22 MANAGEMENT: CMD 'hold release'
2017-07-10 23:13:22 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:13:22 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:13:22 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:13:22 MANAGEMENT: >STATE:1499699602,RESOLVE,,,
2017-07-10 23:13:22 UDPv4 link local: [undef]
2017-07-10 23:13:22 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:13:22 MANAGEMENT: >STATE:1499699602,WAIT,,,
2017-07-10 23:14:23 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:14:23 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:14:23 TLS Error: TLS handshake failed
2017-07-10 23:14:23 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:14:23 MANAGEMENT: >STATE:1499699663,RECONNECTING,tls-error,,
2017-07-10 23:14:23 MANAGEMENT: CMD 'hold release'
2017-07-10 23:14:23 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:14:23 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:14:23 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:14:23 MANAGEMENT: >STATE:1499699663,RESOLVE,,,
2017-07-10 23:14:23 UDPv4 link local: [undef]
2017-07-10 23:14:23 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:14:23 MANAGEMENT: >STATE:1499699663,WAIT,,,
2017-07-10 23:15:23 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:15:23 TLS Error: TLS handshake failed
2017-07-10 23:15:23 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:15:23 MANAGEMENT: >STATE:1499699723,RECONNECTING,tls-error,,
2017-07-10 23:15:23 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:15:23 MANAGEMENT: CMD 'hold release'
2017-07-10 23:15:23 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:15:23 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:15:23 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:15:23 MANAGEMENT: >STATE:1499699723,RESOLVE,,,
2017-07-10 23:15:23 UDPv4 link local: [undef]
2017-07-10 23:15:23 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:15:23 MANAGEMENT: >STATE:1499699723,WAIT,,,
2017-07-10 23:16:23 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:16:23 TLS Error: TLS handshake failed
2017-07-10 23:16:23 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:16:23 MANAGEMENT: >STATE:1499699783,RECONNECTING,tls-error,,
2017-07-10 23:16:23 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:16:23 MANAGEMENT: CMD 'hold release'
2017-07-10 23:16:23 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:16:23 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:16:23 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:16:23 MANAGEMENT: >STATE:1499699783,RESOLVE,,,
2017-07-10 23:16:23 UDPv4 link local: [undef]
2017-07-10 23:16:23 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:16:23 MANAGEMENT: >STATE:1499699783,WAIT,,,
2017-07-10 23:16:34 *Tunnelblick: Disconnecting; notification window disconnect button pressed
2017-07-10 23:16:34 *Tunnelblick: No 'pre-disconnect.sh' script to execute
2017-07-10 23:16:34 *Tunnelblick: Disconnecting using 'kill'
2017-07-10 23:16:34 event_wait : Interrupted system call (code=4)
2017-07-10 23:16:34 SIGTERM[hard,] received, process exiting
2017-07-10 23:16:34 MANAGEMENT: >STATE:1499699794,EXITING,SIGTERM,,
2017-07-10 23:16:35 *Tunnelblick: No 'post-disconnect.sh' script to execute
2017-07-10 23:16:35 *Tunnelblick: Expected disconnection occurred.

================================================================================


wowiesy
OpenVPN User
Posts: 25
Joined: Mon Jul 10, 2017 6:33 am

Re: New UBUNTU server 16.04: Openvpn routing and firewall setup -> HELP!

Post by wowiesy » Mon Jul 10, 2017 4:59 pm

here's the client log from Mac client:

Code: Select all

*Tunnelblick: OS X 10.11.5; Tunnelblick 3.7.1b (build 4813); prior version 3.7.1a (build 4812); Admin user
git commit ea4b9e30939b4dfd3b69a71f62e91625fa8dd97f


Configuration U1010

"Sanitized" condensed configuration file for /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk:

client
dev tun
proto udp
remote u1010.duckdns.org 1194
resolv-retry infinite
nobind
persist-key
persist-tun
ca ca.crt
cert KSS1XMAC.crt
key KSS1XMAC.key
tls-auth ta.key 1
comp-lzo
verb 5


================================================================================

Non-Apple kexts that are loaded:

Index Refs Address            Size       Wired      Name (Version) UUID <Linked Against>
   24    0 0xffffff7f81277000 0x18000    0x18000    com.rim.driver.BlackBerryUSBDriverInt (0.0.74) 18378BE7-8E39-EE32-58BF-0DD52AA71357 <23 22 21 20 18 5 4 3 1>
  137    3 0xffffff7f82dac000 0x60000    0x60000    org.virtualbox.kext.VBoxDrv (5.0.10) 23DD0853-7210-3AF2-85FA-1C7FF8F7D1BF <7 5 4 3 1>
  143    0 0xffffff7f82e0c000 0x8000     0x8000     org.virtualbox.kext.VBoxUSB (5.0.10) C5D33477-F93D-36AD-8748-1EB1105FB93A <142 137 18 7 5 4 3 1>
  144    0 0xffffff7f82e14000 0x5000     0x5000     org.virtualbox.kext.VBoxNetFlt (5.0.10) E5ABC825-5396-34A7-9B63-3A38E9142EEC <137 7 5 4 3 1>
  145    0 0xffffff7f82e19000 0x6000     0x6000     org.virtualbox.kext.VBoxNetAdp (5.0.10) BEFC91DC-800F-3F16-8388-50584243FB30 <137 5 4 1>

================================================================================

There are no unusual files in U1010.tblk

================================================================================

Configuration preferences:

-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 1
-lastConnectionSucceeded = 0
-tunnelDownSoundName = None
-tunnelUpSoundName = None

================================================================================

Wildcard preferences:

-notOKToCheckThatIPAddressDidNotChangeAfterConnection = 1

================================================================================

Program preferences:

skipWarningAboutPlacingIconNearTheSpotlightIcon = 1
placeIconInStandardPositionInStatusBar = 0
launchAtNextLogin = 1
notOKToCheckThatIPAddressDidNotChangeAfterConnection = 1
askedUserIfOKToCheckThatIPAddressDidNotChangeAfterConnection = 1
tunnelblickVersionHistory = (
    "3.7.1b (build 4813)",
    "3.7.1a (build 4812)",
    "3.7.1 (build 4811)",
    "3.7.0 (build 4790)",
    "3.6.10 (build 4760)",
    "3.6.9 (build 4685)",
    "3.6.8 (build 4625)",
    "3.6.3 (build 4560)",
    "3.4.4 (build 4055.4236)",
    "3.6.0a (build 4543.4546)"
)
lastLaunchTime = 521155278.018634
showConnectedDurations = 1
lastLanguageAtLaunchWasRTL = 0
connectionWindowDisplayCriteria = showWhenConnecting
maxLogDisplaySize = 102400
lastConnectedDisplayName = U1010
keyboardShortcutIndex = 1
updateCheckAutomatically = 1
updateSendProfileInfo = 1
NSWindow Frame ConnectingWindow = 445 449 389 187 0 0 1280 777 
NSWindow Frame SUStatusFrame = 816 437 400 129 0 0 1280 777 
NSWindow Frame SUUpdateAlert = 330 295 620 392 0 0 1280 777 
detailsWindowFrameVersion = 4813
detailsWindowFrame = {{180, 238}, {920, 468}}
detailsWindowLeftFrame = {{0, 0}, {165, 350}}
detailsWindowViewIndex = 0
detailsWindowConfigurationsTabIdentifier = log
leftNavSelectedDisplayName = U1010
AdvancedWindowTabIdentifier = connectingAndDisconnecting
haveDealtWithSparkle1dot5b6 = 1
haveDealtWithOldTunTapPreferences = 1
haveDealtWithOldLoginItem = 1
SUEnableAutomaticChecks = 1
SUFeedURL = https://www.tunnelblick.net/appcast-s.rss
SUScheduledCheckInterval = 86400
SUSendProfileInfo = 1
SULastCheckTime = 2017-07-07 21:21:23 +0000
SULastProfileSubmissionDate = 2017-07-07 12:42:24 +0000
SUHasLaunchedBefore = 1
WebKitDefaultFontSize = 11
WebKitStandardFont = .AppleSystemUIFont
tunnelblickdHash = 982f7a7b2b98739801aa88b72712259b30dea31dbe8f2662db447888ff2ff295
tunnelblickdPlistHash = ce400d395d1801b003398461b5420021f4d591822783a04b79b2f43956d28620

================================================================================

Tunnelblick Log:

2017-07-10 23:07:18 OpenVPN 2.3.17 x86_64-apple-darwin [SSL (OpenSSL)] [LZO] [PKCS11] [MH] [IPv6] built on Jun 21 2017
2017-07-10 23:07:18 library versions: OpenSSL 1.0.2k  26 Jan 2017, LZO 2.09
2017-07-10 23:07:18 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:1337
2017-07-10 23:07:18 Need hold release from management interface, waiting...
*Tunnelblick: OS X 10.11.5; Tunnelblick 3.7.1b (build 4813); prior version 3.7.1a (build 4812)
2017-07-10 23:07:18 *Tunnelblick: Attempting connection with U1010 using shadow copy; Set nameserver = 769; monitoring connection
2017-07-10 23:07:18 *Tunnelblick: openvpnstart start U1010.tblk 1337 769 0 1 0 1065264 -ptADGNWradsgnw 2.3.17-openssl-1.0.2k
2017-07-10 23:07:19 *Tunnelblick: openvpnstart log:
     OpenVPN started successfully. Command used to start OpenVPN (one argument per displayed line):
     
          /Applications/Tunnelblick.app/Contents/Resources/openvpn/openvpn-2.3.17-openssl-1.0.2k/openvpn
          --daemon
          --log
          /Library/Application Support/Tunnelblick/Logs/-SUsers-Skss1x-SLibrary-SApplication Support-STunnelblick-SConfigurations-SU1010.tblk-SContents-SResources-Sconfig.ovpn.769_0_1_0_1065264.1337.openvpn.log
          --cd
          /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
          --verb
          3
          --config
          /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
          --verb
          3
          --cd
          /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
          --management
          127.0.0.1
          1337
          --management-query-passwords
          --management-hold
          --script-security
          2
          --up
          /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw
          --down
          /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -9 -d -f -m -w -ptADGNWradsgnw

2017-07-10 23:07:18 *Tunnelblick: openvpnstart starting OpenVPN
2017-07-10 23:07:19 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:1337
2017-07-10 23:07:19 MANAGEMENT: CMD 'pid'
2017-07-10 23:07:19 MANAGEMENT: CMD 'state on'
2017-07-10 23:07:19 MANAGEMENT: CMD 'state'
2017-07-10 23:07:19 MANAGEMENT: CMD 'bytecount 1'
2017-07-10 23:07:19 MANAGEMENT: CMD 'hold release'
2017-07-10 23:07:19 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:07:19 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:07:19 Control Channel Authentication: using 'ta.key' as a OpenVPN static key file
2017-07-10 23:07:19 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
2017-07-10 23:07:19 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication
2017-07-10 23:07:19 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:07:19 MANAGEMENT: >STATE:1499699239,RESOLVE,,,
2017-07-10 23:07:19 *Tunnelblick: Established communication with OpenVPN
2017-07-10 23:07:20 UDPv4 link local: [undef]
2017-07-10 23:07:20 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:07:20 MANAGEMENT: >STATE:1499699240,WAIT,,,
2017-07-10 23:08:20 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:08:20 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:08:20 TLS Error: TLS handshake failed
2017-07-10 23:08:20 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:08:20 MANAGEMENT: >STATE:1499699300,RECONNECTING,tls-error,,
2017-07-10 23:08:20 MANAGEMENT: CMD 'hold release'
2017-07-10 23:08:20 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:08:20 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:08:20 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:08:20 MANAGEMENT: >STATE:1499699300,RESOLVE,,,
2017-07-10 23:08:20 UDPv4 link local: [undef]
2017-07-10 23:08:20 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:08:20 MANAGEMENT: >STATE:1499699300,WAIT,,,
2017-07-10 23:09:20 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:09:20 TLS Error: TLS handshake failed
2017-07-10 23:09:20 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:09:20 MANAGEMENT: >STATE:1499699360,RECONNECTING,tls-error,,
2017-07-10 23:09:21 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:09:21 MANAGEMENT: CMD 'hold release'
2017-07-10 23:09:21 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:09:21 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:09:21 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:09:21 MANAGEMENT: >STATE:1499699361,RESOLVE,,,
2017-07-10 23:09:21 UDPv4 link local: [undef]
2017-07-10 23:09:21 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:09:21 MANAGEMENT: >STATE:1499699361,WAIT,,,
2017-07-10 23:10:21 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:10:21 TLS Error: TLS handshake failed
2017-07-10 23:10:21 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:10:21 MANAGEMENT: >STATE:1499699421,RECONNECTING,tls-error,,
2017-07-10 23:10:21 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:10:21 MANAGEMENT: CMD 'hold release'
2017-07-10 23:10:21 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:10:21 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:10:21 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:10:21 MANAGEMENT: >STATE:1499699421,RESOLVE,,,
2017-07-10 23:10:21 UDPv4 link local: [undef]
2017-07-10 23:10:21 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:10:21 MANAGEMENT: >STATE:1499699421,WAIT,,,
2017-07-10 23:11:21 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:11:21 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:11:21 TLS Error: TLS handshake failed
2017-07-10 23:11:21 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:11:21 MANAGEMENT: >STATE:1499699481,RECONNECTING,tls-error,,
2017-07-10 23:11:21 MANAGEMENT: CMD 'hold release'
2017-07-10 23:11:21 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:11:21 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:11:21 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:11:21 MANAGEMENT: >STATE:1499699481,RESOLVE,,,
2017-07-10 23:11:21 UDPv4 link local: [undef]
2017-07-10 23:11:21 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:11:21 MANAGEMENT: >STATE:1499699481,WAIT,,,
2017-07-10 23:12:21 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:12:21 TLS Error: TLS handshake failed
2017-07-10 23:12:21 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:12:21 MANAGEMENT: >STATE:1499699541,RECONNECTING,tls-error,,
2017-07-10 23:12:21 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:12:21 MANAGEMENT: CMD 'hold release'
2017-07-10 23:12:21 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:12:21 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:12:21 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:12:21 MANAGEMENT: >STATE:1499699541,RESOLVE,,,
2017-07-10 23:12:22 UDPv4 link local: [undef]
2017-07-10 23:12:22 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:12:22 MANAGEMENT: >STATE:1499699542,WAIT,,,
2017-07-10 23:13:22 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:13:22 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:13:22 TLS Error: TLS handshake failed
2017-07-10 23:13:22 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:13:22 MANAGEMENT: >STATE:1499699602,RECONNECTING,tls-error,,
2017-07-10 23:13:22 MANAGEMENT: CMD 'hold release'
2017-07-10 23:13:22 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:13:22 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:13:22 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:13:22 MANAGEMENT: >STATE:1499699602,RESOLVE,,,
2017-07-10 23:13:22 UDPv4 link local: [undef]
2017-07-10 23:13:22 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:13:22 MANAGEMENT: >STATE:1499699602,WAIT,,,
2017-07-10 23:14:23 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:14:23 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:14:23 TLS Error: TLS handshake failed
2017-07-10 23:14:23 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:14:23 MANAGEMENT: >STATE:1499699663,RECONNECTING,tls-error,,
2017-07-10 23:14:23 MANAGEMENT: CMD 'hold release'
2017-07-10 23:14:23 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:14:23 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:14:23 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:14:23 MANAGEMENT: >STATE:1499699663,RESOLVE,,,
2017-07-10 23:14:23 UDPv4 link local: [undef]
2017-07-10 23:14:23 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:14:23 MANAGEMENT: >STATE:1499699663,WAIT,,,
2017-07-10 23:15:23 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:15:23 TLS Error: TLS handshake failed
2017-07-10 23:15:23 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:15:23 MANAGEMENT: >STATE:1499699723,RECONNECTING,tls-error,,
2017-07-10 23:15:23 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:15:23 MANAGEMENT: CMD 'hold release'
2017-07-10 23:15:23 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:15:23 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:15:23 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:15:23 MANAGEMENT: >STATE:1499699723,RESOLVE,,,
2017-07-10 23:15:23 UDPv4 link local: [undef]
2017-07-10 23:15:23 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:15:23 MANAGEMENT: >STATE:1499699723,WAIT,,,
2017-07-10 23:16:23 TLS Error: TLS key negotiation failed to occur within 60 seconds (check your network connectivity)
2017-07-10 23:16:23 TLS Error: TLS handshake failed
2017-07-10 23:16:23 SIGUSR1[soft,tls-error] received, process restarting
2017-07-10 23:16:23 MANAGEMENT: >STATE:1499699783,RECONNECTING,tls-error,,
2017-07-10 23:16:23 *Tunnelblick: No 'reconnecting.sh' script to execute
2017-07-10 23:16:23 MANAGEMENT: CMD 'hold release'
2017-07-10 23:16:23 WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
2017-07-10 23:16:23 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2017-07-10 23:16:23 Socket Buffers: R=[196724->196724] S=[9216->9216]
2017-07-10 23:16:23 MANAGEMENT: >STATE:1499699783,RESOLVE,,,
2017-07-10 23:16:23 UDPv4 link local: [undef]
2017-07-10 23:16:23 UDPv4 link remote: [AF_INET]112.209.35.12:1194
2017-07-10 23:16:23 MANAGEMENT: >STATE:1499699783,WAIT,,,
2017-07-10 23:16:34 *Tunnelblick: Disconnecting; notification window disconnect button pressed
2017-07-10 23:16:34 *Tunnelblick: No 'pre-disconnect.sh' script to execute
2017-07-10 23:16:34 *Tunnelblick: Disconnecting using 'kill'
2017-07-10 23:16:34 event_wait : Interrupted system call (code=4)
2017-07-10 23:16:34 SIGTERM[hard,] received, process exiting
2017-07-10 23:16:34 MANAGEMENT: >STATE:1499699794,EXITING,SIGTERM,,
2017-07-10 23:16:35 *Tunnelblick: No 'post-disconnect.sh' script to execute
2017-07-10 23:16:35 *Tunnelblick: Expected disconnection occurred.

================================================================================

"Sanitized" full configuration file

##############################################
# Sample client-side OpenVPN 2.0 config file #
# for connecting to multi-client server.     #
#                                            #
# This configuration can be used by multiple #
# clients, however each client should have   #
# its own cert and key files.                #
#                                            #
# On Windows, you might want to rename this  #
# file so it has a .ovpn extension           #
##############################################

# Specify that we are a client and that we
# will be pulling certain config file directives
# from the server.
client

# Use the same setting as you are using on
# the server.
# On most systems, the VPN will not function
# unless you partially or fully disable
# the firewall for the TUN/TAP interface.
;dev tap
dev tun

# Windows needs the TAP-Win32 adapter name
# from the Network Connections panel
# if you have more than one.  On XP SP2,
# you may need to disable the firewall
# for the TAP adapter.
;dev-node MyTap

# Are we connecting to a TCP or
# UDP server?  Use the same setting as
# on the server.
;proto tcp
proto udp

# The hostname/IP and port of the server.
# You can have multiple remote entries
# to load balance between the servers.
;remote 192.168.254.254 1194
;remote u1010.dyndns-ip.com 1194
;remote U1010.no-ip.org 1194
remote u1010.duckdns.org 1194

# Choose a random host from the remote
# list for load-balancing.  Otherwise
# try hosts in the order specified.
;remote-random

# Keep trying indefinitely to resolve the
# host name of the OpenVPN server.  Very useful
# on machines which are not permanently connected
# to the internet such as laptops.
resolv-retry infinite

# Most clients don't need to bind to
# a specific local port number.
nobind

# Downgrade privileges after initialization (non-Windows only)
;user nobody
;group nobody

# Try to preserve some state across restarts.
persist-key
persist-tun

# If you are connecting through an
# HTTP proxy to reach the actual OpenVPN
# server, put the proxy server/IP and
# port number here.  See the man page
# if your proxy server requires
# authentication.
;http-proxy-retry # retry on connection failures
;http-proxy [proxy server] [proxy port #]

# Wireless networks often produce a lot
# of duplicate packets.  Set this flag
# to silence duplicate packet warnings.
;mute-replay-warnings

# SSL/TLS parms.
# See the server config file for more
# description.  It's best to use
# a separate .crt/.key file pair
# for each client.  A single ca
# file can be used for all clients.
# ca /Users/kss1x/Library/openvpn/ca.crt
# cert /Users/kss1x/Library/openvpn/KSS1XMAC.crt 
# key /Users/kss1x/Library/openvpn/KSS1XMAC.key 

ca ca.crt
cert KSS1XMAC.crt
key KSS1XMAC.key

# Verify server certificate by checking
# that the certicate has the nsCertType
# field set to "server".  This is an
# important precaution to protect against
# a potential attack discussed here:
#  http://openvpn.net/howto.html#mitm
#
# To use this feature, you will need to generate
# your server certificates with the nsCertType
# field set to "server".  The build-key-server
# script in the easy-rsa folder will do this.
;ns-cert-type server

# If a tls-auth key is used on the server
# then every client must also have the key.
tls-auth ta.key 1

# Select a cryptographic cipher.
# If the cipher option is used on the server
# then you must also specify it here.
;cipher x

# Enable compression on the VPN link.
# Don't enable this unless it is also
# enabled in the server config file.
comp-lzo

# Set log file verbosity.
verb 5

# Silence repeating messages
;mute 20



================================================================================

ifconfig output:

lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
	options=3<RXCSUM,TXCSUM>
	inet6 ::1 prefixlen 128 
	inet 127.0.0.1 netmask 0xff000000 
	inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1 
	nd6 options=1<PERFORMNUD>
gif0: flags=8010<POINTOPOINT,MULTICAST> mtu 1280
stf0: flags=0<> mtu 1280
en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
	options=27<RXCSUM,TXCSUM,VLAN_MTU,TSO4>
	ether 34:15:9e:23:1e:80 
	nd6 options=1<PERFORMNUD>
	media: autoselect
	status: inactive
en1: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
	ether 00:26:bb:0a:71:92 
	inet6 fe80::226:bbff:fe0a:7192%en1 prefixlen 64 scopeid 0x5 
	inet 192.168.254.210 netmask 0xffffff00 broadcast 192.168.254.255
	nd6 options=1<PERFORMNUD>
	media: autoselect
	status: active
fw0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 4078
	lladdr 34:15:9e:ff:fe:23:1e:80 
	nd6 options=1<PERFORMNUD>
	media: autoselect <full-duplex>
	status: inactive
p2p0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 2304
	ether 02:26:bb:0a:71:92 
	media: autoselect
	status: inactive

================================================================================

Console Log:

2017-07-10 21:44:47 tunnelblickd[2698] Status = 252 from tunnelblick-helper command 'compareShadowCopy U1010'
2017-07-10 21:44:47 Tunnelblick[568] tunnelblickd status from compareShadowCopy: 252
2017-07-10 21:44:54 Tunnelblick[568] Tunnelblick needs to perform an action that requires administrator authorization.
2017-07-10 21:44:54 Tunnelblick[568] Beginning installation or repair
2017-07-10 21:44:54 authexec[2709] executing /Applications/Tunnelblick.app/Contents/Resources/installer
2017-07-10 21:44:54 Tunnelblick[568] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-07-10 21:44:54. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                            /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                       Copied /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                           to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished without error
2017-07-10 21:44:54 Tunnelblick[568] Created or updated secure (shadow) copy of configuration file /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
2017-07-10 22:04:04 tunnelblickd[2888] Status = 252 from tunnelblick-helper command 'compareShadowCopy U1010'
2017-07-10 22:04:04 Tunnelblick[568] tunnelblickd status from compareShadowCopy: 252
2017-07-10 22:04:10 Tunnelblick[568] Tunnelblick needs to perform an action that requires administrator authorization.
2017-07-10 22:04:10 Tunnelblick[568] Beginning installation or repair
2017-07-10 22:04:10 authexec[2903] executing /Applications/Tunnelblick.app/Contents/Resources/installer
2017-07-10 22:04:10 Tunnelblick[568] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-07-10 22:04:10. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                            /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                       Copied /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                           to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished without error
2017-07-10 22:04:10 Tunnelblick[568] Created or updated secure (shadow) copy of configuration file /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
2017-07-10 22:05:09 tunnelblickd[2888] Status = 252 from tunnelblick-helper command 'compareShadowCopy U1010'
2017-07-10 22:05:09 Tunnelblick[568] tunnelblickd status from compareShadowCopy: 252
2017-07-10 22:05:14 Tunnelblick[568] Tunnelblick needs to perform an action that requires administrator authorization.
2017-07-10 22:05:14 Tunnelblick[568] Beginning installation or repair
2017-07-10 22:05:14 authexec[2989] executing /Applications/Tunnelblick.app/Contents/Resources/installer
2017-07-10 22:05:14 Tunnelblick[568] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-07-10 22:05:14. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                            /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                       Copied /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                           to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished without error
2017-07-10 22:05:14 Tunnelblick[568] Created or updated secure (shadow) copy of configuration file /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
2017-07-10 22:47:25 tunnelblickd[3158] Status = 252 from tunnelblick-helper command 'compareShadowCopy U1010'
2017-07-10 22:47:25 Tunnelblick[568] tunnelblickd status from compareShadowCopy: 252
2017-07-10 22:47:33 Tunnelblick[568] Tunnelblick needs to perform an action that requires administrator authorization.
2017-07-10 22:47:33 Tunnelblick[568] Beginning installation or repair
2017-07-10 22:47:33 authexec[3173] executing /Applications/Tunnelblick.app/Contents/Resources/installer
2017-07-10 22:47:33 Tunnelblick[568] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-07-10 22:47:33. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                            /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                       Copied /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                           to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished without error
2017-07-10 22:47:33 Tunnelblick[568] Created or updated secure (shadow) copy of configuration file /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
2017-07-10 22:53:55 tunnelblickd[3270] Status = 252 from tunnelblick-helper command 'compareShadowCopy U1010'
2017-07-10 22:53:55 Tunnelblick[568] tunnelblickd status from compareShadowCopy: 252
2017-07-10 22:54:01 Tunnelblick[568] Tunnelblick needs to perform an action that requires administrator authorization.
2017-07-10 22:54:01 Tunnelblick[568] Beginning installation or repair
2017-07-10 22:54:01 authexec[3276] executing /Applications/Tunnelblick.app/Contents/Resources/installer
2017-07-10 22:54:01 Tunnelblick[568] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-07-10 22:54:01. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                            /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                       Copied /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                           to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished without error
2017-07-10 22:54:01 Tunnelblick[568] Created or updated secure (shadow) copy of configuration file /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
2017-07-10 22:54:02 tunnelblickd[3270] Status = 251 from tunnelblick-helper command 'start U1010.tblk 1337 769 0 1 0 1065264 -ptADGNWradsgnw 2.3.17-openssl-1.0.2k'
2017-07-10 22:54:02 Tunnelblick[568] tunnelblickd status from start: 251
2017-07-10 22:54:26 tunnelblickd[3270] Status = 252 from tunnelblick-helper command 'compareShadowCopy U1010'
2017-07-10 22:54:26 Tunnelblick[568] tunnelblickd status from compareShadowCopy: 252
2017-07-10 22:54:32 Tunnelblick[568] Tunnelblick needs to perform an action that requires administrator authorization.
2017-07-10 22:54:32 Tunnelblick[568] Beginning installation or repair
2017-07-10 22:54:32 authexec[3288] executing /Applications/Tunnelblick.app/Contents/Resources/installer
2017-07-10 22:54:32 Tunnelblick[568] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-07-10 22:54:32. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                            /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                       Copied /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                           to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished without error
2017-07-10 22:54:32 Tunnelblick[568] Created or updated secure (shadow) copy of configuration file /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
2017-07-10 23:02:09 tunnelblickd[3328] Status = 252 from tunnelblick-helper command 'compareShadowCopy U1010'
2017-07-10 23:02:09 Tunnelblick[568] tunnelblickd status from compareShadowCopy: 252
2017-07-10 23:02:15 Tunnelblick[568] Tunnelblick needs to perform an action that requires administrator authorization.
2017-07-10 23:02:15 Tunnelblick[568] Beginning installation or repair
2017-07-10 23:02:15 authexec[3339] executing /Applications/Tunnelblick.app/Contents/Resources/installer
2017-07-10 23:02:15 Tunnelblick[568] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-07-10 23:02:15. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                            /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                       Copied /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                           to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished without error
2017-07-10 23:02:15 Tunnelblick[568] Created or updated secure (shadow) copy of configuration file /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
2017-07-10 23:07:11 tunnelblickd[3432] Status = 252 from tunnelblick-helper command 'compareShadowCopy U1010'
2017-07-10 23:07:11 Tunnelblick[568] tunnelblickd status from compareShadowCopy: 252
2017-07-10 23:07:18 Tunnelblick[568] Tunnelblick needs to perform an action that requires administrator authorization.
2017-07-10 23:07:18 Tunnelblick[568] Beginning installation or repair
2017-07-10 23:07:18 authexec[3438] executing /Applications/Tunnelblick.app/Contents/Resources/installer
2017-07-10 23:07:18 Tunnelblick[568] Installation or repair succeeded; Log:
                                       Tunnelblick installer started 2017-07-10 23:07:18. 3 arguments: 0x0001
                                            /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                            /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                       Copied /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
                                           to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                       Renamed /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk.temp
                                            to /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed ownership of /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk and its contents from 501:80 to 0:0
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents
                                       Changed permissions from 750 to 755 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ca.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/config.ovpn
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.crt
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/KSS1XMAC.key
                                       Changed permissions from 740 to 700 on /Library/Application Support/Tunnelblick/Users/kss1x/U1010.tblk/Contents/Resources/ta.key
                                       Tunnelblick installer finished without error
2017-07-10 23:07:18 Tunnelblick[568] Created or updated secure (shadow) copy of configuration file /Users/kss1x/Library/Application Support/Tunnelblick/Configurations/U1010.tblk
2017-07-10 23:49:29 Tunnelblick[568] Communications error: <OS_xpc_error: <error: 0x7fff72c3db90> { count = 1, contents =
                                       	"XPCErrorDescription" => <string: 0x7fff72c3df40> { length = 22, contents = "Connection interrupted" }
                                       }>
2017-07-10 23:57:45 kernel[0] PM response took 775 ms (568, Tunnelblick)


wowiesy
OpenVPN User
Posts: 25
Joined: Mon Jul 10, 2017 6:33 am

Re: New UBUNTU server 16.04: Openvpn routing and firewall setup -> HELP!

Post by wowiesy » Wed Jul 12, 2017 7:18 pm

I did a thorough check on my setup.. from the modem to the router..

and BAM! I didn't have a port forwarding entry in the modem to my ubuntu router...

so I put in the settings.. and I was able to move on... VPN connected from LTE network..

sheesh.. this is too basic a step that I missed...

TinCanTech
OpenVPN Protagonist
Posts: 11137
Joined: Fri Jun 03, 2016 1:17 pm

Re: New UBUNTU server 16.04: Openvpn routing and firewall setup -> HELP!

Post by TinCanTech » Wed Jul 12, 2017 8:37 pm

Nice ! (we all make mistakes)

Thanks for letting us know 8-)

Post Reply