ok, you wanted the routing table and I had made a few changes to the config and found some weirdness going on so forgive me if I divert a bit here. I changed my server config based on information found here (
http://www.secure-computing.net/wiki/in ... PN/Routing ) as suggested bot the bot on IRC. I do not know why it is crating these routes to 10.8.0.5 as that interface does not exist on the server and isn't routable. If I manually reconstruct the routes to use 10.8.0.1 as the gateway some stuff works. I can then ssh to 10.2.2.5 but I can not use safari or firefox to pull up the webserver there. 10.2.2.5 has routes to 10.8.0.0/24 via 10.2.2.50 which is the vpn server.
edited server.conf
Code: Select all
local 64.141.147.212
port 1194
proto udp
dev tun
ca /usr/local/etc/openvpn/keys/ca.crt
cert /usr/local/etc/openvpn/keys/server.crt
key /usr/local/etc/openvpn/keys/server.key # This file should be kept secret
dh /usr/local/etc/openvpn/keys/dh2048.pem
server 10.8.0.0 255.255.255.0
ifconfig-pool-persist ipp.txt
route 10.8.0.0 255.255.255.0
route 10.2.2.0 255.255.255.0
push "route 10.2.2.0 255.255.255.0"
push "route 10.8.0.0 255.255.255.0"
keepalive 10 120
comp-lzo
persist-key
persist-tun
status openvpn-status.log
log openvpn.log
log-append openvpn.log
verb 4
ifconfig server
Code: Select all
em0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
options=9b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,VLAN_HWCSUM>
ether 00:0c:29:d7:77:44
inet 64.141.147.212 netmask 0xffffff00 broadcast 64.141.147.255
inet6 fe80::20c:29ff:fed7:7744%em0 prefixlen 64 scopeid 0x1
nd6 options=3<PERFORMNUD,ACCEPT_RTADV>
media: Ethernet autoselect (1000baseT <full-duplex>)
status: active
em1: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
options=9b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,VLAN_HWCSUM>
ether 00:0c:29:d7:77:4e
inet 10.2.2.51 netmask 0xffffff00 broadcast 10.2.2.255
inet6 fe80::20c:29ff:fed7:774e%em1 prefixlen 64 scopeid 0x2
nd6 options=3<PERFORMNUD,ACCEPT_RTADV>
media: Ethernet autoselect (1000baseT <full-duplex>)
status: active
plip0: flags=8810<POINTOPOINT,SIMPLEX,MULTICAST> metric 0 mtu 1500
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384
options=3<RXCSUM,TXCSUM>
inet 127.0.0.1 netmask 0xff000000
inet6 ::1 prefixlen 128
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x4
nd6 options=3<PERFORMNUD,ACCEPT_RTADV>
pflog0: flags=0<> metric 0 mtu 33200
tun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> metric 0 mtu 1500
options=80000<LINKSTATE>
inet6 fe80::20c:29ff:fed7:7744%tun0 prefixlen 64 scopeid 0x6
inet 10.8.0.1 --> 10.8.0.2 netmask 0xffffffff
nd6 options=3<PERFORMNUD,ACCEPT_RTADV>
Opened by PID 1117
server: netstat -nr
Code: Select all
Routing tables
Internet:
Destination Gateway Flags Refs Use Netif Expire
default 64.141.147.193 UGS 1 664 em0
10.2.2.0/24 link#2 U 0 24 em1
10.2.2.51 link#2 UHS 0 0 lo0
10.8.0.0/24 10.8.0.2 UGS 0 134 tun0
10.8.0.1 link#6 UHS 0 0 lo0
10.8.0.2 link#6 UH 0 0 tun0
64.141.147.0/24 link#1 U 0 0 em0
64.141.147.212 link#1 UHS 0 0 lo0
127.0.0.1 link#4 UH 0 0 lo0
client log
Code: Select all
2011-01-07 12:01:41 *Tunnelblick: OS X 10.6.6; Tunnelblick 3.1.2 (build 2190.2258); OpenVPN 2.1.4
2011-01-07 12:01:45 *Tunnelblick: Attempting connection with config; Set nameserver = 1; monitoring connection
2011-01-07 12:01:45 *Tunnelblick: /Applications/Tunnelblick.app/Contents/Resources/openvpnstart start config.ovpn 1338 1 0 0 0 49
2011-01-07 12:01:45 us=647628 Current Parameter Settings:
2011-01-07 12:01:45 us=647819 config = '/Users/iceberg/Library/Application Support/Tunnelblick/Configurations/config.ovpn'
2011-01-07 12:01:45 us=647831 mode = 0
2011-01-07 12:01:45 us=647841 show_ciphers = DISABLED
2011-01-07 12:01:45 us=647850 show_digests = DISABLED
2011-01-07 12:01:45 us=647859 show_engines = DISABLED
2011-01-07 12:01:45 us=647868 genkey = DISABLED
2011-01-07 12:01:45 us=647878 key_pass_file = '[UNDEF]'
2011-01-07 12:01:45 us=647887 show_tls_ciphers = DISABLED
2011-01-07 12:01:45 us=647896 Connection profiles [default]:
2011-01-07 12:01:45 us=647906 proto = udp
2011-01-07 12:01:45 us=647919 local = '[UNDEF]'
2011-01-07 12:01:45 us=647929 local_port = 0
2011-01-07 12:01:45 us=647939 remote = '64.141.147.212'
2011-01-07 12:01:45 us=647948 remote_port = 1194
2011-01-07 12:01:45 us=647957 remote_float = DISABLED
2011-01-07 12:01:45 us=647966 bind_defined = DISABLED
2011-01-07 12:01:45 us=647975 bind_local = DISABLED
2011-01-07 12:01:45 us=647985 connect_retry_seconds = 5
2011-01-07 12:01:45 us=647994 connect_timeout = 10
2011-01-07 12:01:45 us=648004 connect_retry_max = 0
2011-01-07 12:01:45 us=648013 socks_proxy_server = '[UNDEF]'
2011-01-07 12:01:45 us=648022 socks_proxy_port = 0
2011-01-07 12:01:45 us=648032 socks_proxy_retry = DISABLED
2011-01-07 12:01:45 us=648041 Connection profiles END
2011-01-07 12:01:45 us=648050 remote_random = DISABLED
2011-01-07 12:01:45 us=648059 ipchange = '[UNDEF]'
2011-01-07 12:01:45 us=648068 dev = 'tun'
2011-01-07 12:01:45 us=648078 dev_type = '[UNDEF]'
2011-01-07 12:01:45 us=648087 dev_node = '[UNDEF]'
2011-01-07 12:01:45 us=648096 lladdr = '[UNDEF]'
2011-01-07 12:01:45 us=648106 topology = 1
2011-01-07 12:01:45 us=648115 tun_ipv6 = DISABLED
2011-01-07 12:01:45 us=648124 ifconfig_local = '[UNDEF]'
2011-01-07 12:01:45 us=648133 ifconfig_remote_netmask = '[UNDEF]'
2011-01-07 12:01:45 us=648143 ifconfig_noexec = DISABLED
2011-01-07 12:01:45 us=648152 ifconfig_nowarn = DISABLED
2011-01-07 12:01:45 us=648161 shaper = 0
2011-01-07 12:01:45 us=648170 tun_mtu = 1500
2011-01-07 12:01:45 us=648180 tun_mtu_defined = ENABLED
2011-01-07 12:01:45 us=648189 link_mtu = 1500
2011-01-07 12:01:45 us=648198 link_mtu_defined = DISABLED
2011-01-07 12:01:45 us=648207 tun_mtu_extra = 0
2011-01-07 12:01:45 us=648217 tun_mtu_extra_defined = DISABLED
2011-01-07 12:01:45 us=648226 fragment = 0
2011-01-07 12:01:45 us=648235 mtu_discover_type = -1
2011-01-07 12:01:45 us=648244 mtu_test = 0
2011-01-07 12:01:45 us=648254 mlock = DISABLED
2011-01-07 12:01:45 us=648263 keepalive_ping = 0
2011-01-07 12:01:45 us=648272 keepalive_timeout = 0
2011-01-07 12:01:45 us=648281 inactivity_timeout = 0
2011-01-07 12:01:45 us=648291 ping_send_timeout = 0
2011-01-07 12:01:45 us=648300 ping_rec_timeout = 0
2011-01-07 12:01:45 us=648309 ping_rec_timeout_action = 0
2011-01-07 12:01:45 us=648319 ping_timer_remote = DISABLED
2011-01-07 12:01:45 us=648328 remap_sigusr1 = 0
2011-01-07 12:01:45 us=648337 explicit_exit_notification = 0
2011-01-07 12:01:45 us=648347 persist_tun = ENABLED
2011-01-07 12:01:45 us=648356 persist_local_ip = DISABLED
2011-01-07 12:01:45 us=648365 persist_remote_ip = DISABLED
2011-01-07 12:01:45 us=648374 persist_key = ENABLED
2011-01-07 12:01:45 us=648384 mssfix = 1450
2011-01-07 12:01:45 us=648393 passtos = DISABLED
2011-01-07 12:01:45 us=648402 resolve_retry_seconds = 1000000000
2011-01-07 12:01:45 us=648411 username = '[UNDEF]'
2011-01-07 12:01:45 us=648424 groupname = '[UNDEF]'
2011-01-07 12:01:45 us=648433 chroot_dir = '[UNDEF]'
2011-01-07 12:01:45 us=648442 cd_dir = '/Users/iceberg/Library/Application Support/Tunnelblick/Configurations'
2011-01-07 12:01:45 us=648463 writepid = '[UNDEF]'
2011-01-07 12:01:45 us=648473 up_script = '/Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -m -w -d'
2011-01-07 12:01:45 us=648482 down_script = '/Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -m -w -d'
2011-01-07 12:01:45 us=648492 down_pre = DISABLED
2011-01-07 12:01:45 us=648501 up_restart = ENABLED
2011-01-07 12:01:45 us=648510 up_delay = DISABLED
2011-01-07 12:01:45 us=648520 daemon = ENABLED
2011-01-07 12:01:45 us=648529 inetd = 0
2011-01-07 12:01:45 us=648538 log = ENABLED
2011-01-07 12:01:45 us=648547 suppress_timestamps = DISABLED
2011-01-07 12:01:45 us=648557 nice = 0
2011-01-07 12:01:45 us=648566 verbosity = 4
2011-01-07 12:01:45 us=648575 mute = 0
2011-01-07 12:01:45 us=648584 gremlin = 0
2011-01-07 12:01:45 us=648594 status_file = '[UNDEF]'
2011-01-07 12:01:45 us=648603 status_file_version = 1
2011-01-07 12:01:45 us=648612 status_file_update_freq = 60
2011-01-07 12:01:45 us=648621 occ = ENABLED
2011-01-07 12:01:45 us=648631 rcvbuf = 65536
2011-01-07 12:01:45 us=648640 sndbuf = 65536
2011-01-07 12:01:45 us=648649 sockflags = 0
2011-01-07 12:01:45 us=648658 fast_io = DISABLED
2011-01-07 12:01:45 us=648667 lzo = 7
2011-01-07 12:01:45 us=648676 route_script = '[UNDEF]'
2011-01-07 12:01:45 us=648686 route_default_gateway = '[UNDEF]'
2011-01-07 12:01:45 us=648695 route_default_metric = 0
2011-01-07 12:01:45 us=648704 route_noexec = DISABLED
2011-01-07 12:01:45 us=648713 route_delay = 0
2011-01-07 12:01:45 us=648723 route_delay_window = 30
2011-01-07 12:01:45 us=648732 route_delay_defined = DISABLED
2011-01-07 12:01:45 us=648741 route_nopull = DISABLED
2011-01-07 12:01:45 us=648750 route_gateway_via_dhcp = DISABLED
2011-01-07 12:01:45 us=648760 max_routes = 100
2011-01-07 12:01:45 us=648769 allow_pull_fqdn = DISABLED
2011-01-07 12:01:45 us=648779 management_addr = '127.0.0.1'
2011-01-07 12:01:45 us=648789 management_port = 1338
2011-01-07 12:01:45 us=648799 management_user_pass = '[UNDEF]'
2011-01-07 12:01:45 us=648808 management_log_history_cache = 250
2011-01-07 12:01:45 us=648818 management_echo_buffer_size = 100
2011-01-07 12:01:45 us=648828 management_write_peer_info_file = '[UNDEF]'
2011-01-07 12:01:45 us=648838 management_client_user = '[UNDEF]'
2011-01-07 12:01:45 us=648848 management_client_group = '[UNDEF]'
2011-01-07 12:01:45 us=648858 management_flags = 6
2011-01-07 12:01:45 us=648868 shared_secret_file = '[UNDEF]'
2011-01-07 12:01:45 us=648878 key_direction = 0
2011-01-07 12:01:45 us=648887 ciphername_defined = ENABLED
2011-01-07 12:01:45 us=648897 ciphername = 'BF-CBC'
2011-01-07 12:01:45 us=648906 authname_defined = ENABLED
2011-01-07 12:01:45 us=648916 authname = 'SHA1'
2011-01-07 12:01:45 us=648929 prng_hash = 'SHA1'
2011-01-07 12:01:45 us=648939 prng_nonce_secret_len = 16
2011-01-07 12:01:45 us=648951 keysize = 0
2011-01-07 12:01:45 us=648961 engine = DISABLED
2011-01-07 12:01:45 us=648971 replay = ENABLED
2011-01-07 12:01:45 us=648980 mute_replay_warnings = DISABLED
2011-01-07 12:01:45 us=648990 replay_window = 64
2011-01-07 12:01:45 us=649000 replay_time = 15
2011-01-07 12:01:45 us=649009 packet_id_file = '[UNDEF]'
2011-01-07 12:01:45 us=649019 use_iv = ENABLED
2011-01-07 12:01:45 us=649028 test_crypto = DISABLED
2011-01-07 12:01:45 us=649038 tls_server = DISABLED
2011-01-07 12:01:45 us=649048 tls_client = ENABLED
2011-01-07 12:01:45 us=649057 key_method = 2
2011-01-07 12:01:45 us=649067 ca_file = '/Users/iceberg/.keys/ca.crt'
2011-01-07 12:01:45 us=649077 ca_path = '[UNDEF]'
2011-01-07 12:01:45 us=649086 dh_file = '[UNDEF]'
2011-01-07 12:01:45 us=649107 cert_file = '/Users/iceberg/.keys/client.crt'
2011-01-07 12:01:45 us=649117 priv_key_file = '/Users/iceberg/.keys/client.key'
2011-01-07 12:01:45 us=649127 pkcs12_file = '[UNDEF]'
2011-01-07 12:01:45 us=649136 cipher_list = '[UNDEF]'
2011-01-07 12:01:45 us=649146 tls_verify = '[UNDEF]'
2011-01-07 12:01:45 us=649155 tls_remote = '[UNDEF]'
2011-01-07 12:01:45 us=649165 crl_file = '[UNDEF]'
2011-01-07 12:01:45 us=649174 ns_cert_type = 0
2011-01-07 12:01:45 us=649184 remote_cert_ku[i] = 0
2011-01-07 12:01:45 us=649193 remote_cert_ku[i] = 0
2011-01-07 12:01:45 us=649203 remote_cert_ku[i] = 0
2011-01-07 12:01:45 us=649213 remote_cert_ku[i] = 0
2011-01-07 12:01:45 us=649222 remote_cert_ku[i] = 0
2011-01-07 12:01:45 us=649232 remote_cert_ku[i] = 0
2011-01-07 12:01:45 us=649241 remote_cert_ku[i] = 0
2011-01-07 12:01:45 us=649251 remote_cert_ku[i] = 0
2011-01-07 12:01:45 us=649260 remote_cert_ku[i] = 0
2011-01-07 12:01:45 us=649270 remote_cert_ku[i] = 0
2011-01-07 12:01:45 us=649279 remote_cert_ku[i] = 0
2011-01-07 12:01:45 us=649289 remote_cert_ku[i] = 0
2011-01-07 12:01:45 us=649298 remote_cert_ku[i] = 0
2011-01-07 12:01:45 us=649307 remote_cert_ku[i] = 0
2011-01-07 12:01:45 us=649317 remote_cert_ku[i] = 0
2011-01-07 12:01:45 us=649327 remote_cert_ku[i] = 0
2011-01-07 12:01:45 us=649336 remote_cert_eku = '[UNDEF]'
2011-01-07 12:01:45 us=649346 tls_timeout = 2
2011-01-07 12:01:45 us=649356 renegotiate_bytes = 0
2011-01-07 12:01:45 us=649365 renegotiate_packets = 0
2011-01-07 12:01:45 us=649375 renegotiate_seconds = 3600
2011-01-07 12:01:45 us=649385 handshake_window = 60
2011-01-07 12:01:45 us=649394 transition_window = 3600
2011-01-07 12:01:45 us=649404 single_session = DISABLED
2011-01-07 12:01:45 us=649413 push_peer_info = DISABLED
2011-01-07 12:01:45 us=649423 tls_exit = DISABLED
2011-01-07 12:01:45 us=649433 tls_auth_file = '[UNDEF]'
2011-01-07 12:01:45 us=649443 pkcs11_protected_authentication = DISABLED
2011-01-07 12:01:45 us=649452 pkcs11_protected_authentication = DISABLED
2011-01-07 12:01:45 us=649462 pkcs11_protected_authentication = DISABLED
2011-01-07 12:01:45 us=649472 pkcs11_protected_authentication = DISABLED
2011-01-07 12:01:45 us=649482 pkcs11_protected_authentication = DISABLED
2011-01-07 12:01:45 us=649492 pkcs11_protected_authentication = DISABLED
2011-01-07 12:01:45 us=649501 pkcs11_protected_authentication = DISABLED
2011-01-07 12:01:45 us=649511 pkcs11_protected_authentication = DISABLED
2011-01-07 12:01:45 us=649521 pkcs11_protected_authentication = DISABLED
2011-01-07 12:01:45 us=649531 pkcs11_protected_authentication = DISABLED
2011-01-07 12:01:45 us=649540 pkcs11_protected_authentication = DISABLED
2011-01-07 12:01:45 us=649550 pkcs11_protected_authentication = DISABLED
2011-01-07 12:01:45 us=649560 pkcs11_protected_authentication = DISABLED
2011-01-07 12:01:45 us=649570 pkcs11_protected_authentication = DISABLED
2011-01-07 12:01:45 us=649579 pkcs11_protected_authentication = DISABLED
2011-01-07 12:01:45 us=649589 pkcs11_protected_authentication = DISABLED
2011-01-07 12:01:45 us=649599 pkcs11_private_mode = 00000000
2011-01-07 12:01:45 us=649609 pkcs11_private_mode = 00000000
2011-01-07 12:01:45 us=649619 pkcs11_private_mode = 00000000
2011-01-07 12:01:45 us=649629 pkcs11_private_mode = 00000000
2011-01-07 12:01:45 us=649639 pkcs11_private_mode = 00000000
2011-01-07 12:01:45 us=649649 pkcs11_private_mode = 00000000
2011-01-07 12:01:45 us=649659 pkcs11_private_mode = 00000000
2011-01-07 12:01:45 us=649669 pkcs11_private_mode = 00000000
2011-01-07 12:01:45 us=649678 pkcs11_private_mode = 00000000
2011-01-07 12:01:45 us=649688 pkcs11_private_mode = 00000000
2011-01-07 12:01:45 us=649708 pkcs11_private_mode = 00000000
2011-01-07 12:01:45 us=649718 pkcs11_private_mode = 00000000
2011-01-07 12:01:45 us=649728 pkcs11_private_mode = 00000000
2011-01-07 12:01:45 us=649738 pkcs11_private_mode = 00000000
2011-01-07 12:01:45 us=649747 pkcs11_private_mode = 00000000
2011-01-07 12:01:45 us=649757 pkcs11_private_mode = 00000000
2011-01-07 12:01:45 us=649767 pkcs11_cert_private = DISABLED
2011-01-07 12:01:45 us=649777 pkcs11_cert_private = DISABLED
2011-01-07 12:01:45 us=649786 pkcs11_cert_private = DISABLED
2011-01-07 12:01:45 us=649796 pkcs11_cert_private = DISABLED
2011-01-07 12:01:45 us=649806 pkcs11_cert_private = DISABLED
2011-01-07 12:01:45 us=649815 pkcs11_cert_private = DISABLED
2011-01-07 12:01:45 us=649825 pkcs11_cert_private = DISABLED
2011-01-07 12:01:45 us=649834 pkcs11_cert_private = DISABLED
2011-01-07 12:01:45 us=649844 pkcs11_cert_private = DISABLED
2011-01-07 12:01:45 us=649853 pkcs11_cert_private = DISABLED
2011-01-07 12:01:45 us=649863 pkcs11_cert_private = DISABLED
2011-01-07 12:01:45 us=649873 pkcs11_cert_private = DISABLED
2011-01-07 12:01:45 us=649883 pkcs11_cert_private = DISABLED
2011-01-07 12:01:45 us=649897 pkcs11_cert_private = DISABLED
2011-01-07 12:01:45 us=649907 pkcs11_cert_private = DISABLED
2011-01-07 12:01:45 us=649917 pkcs11_cert_private = DISABLED
2011-01-07 12:01:45 us=649927 pkcs11_pin_cache_period = -1
2011-01-07 12:01:45 us=649937 pkcs11_id = '[UNDEF]'
2011-01-07 12:01:45 us=649947 pkcs11_id_management = DISABLED
2011-01-07 12:01:45 us=649963 server_network = 0.0.0.0
2011-01-07 12:01:45 us=649974 server_netmask = 0.0.0.0
2011-01-07 12:01:45 us=649989 server_bridge_ip = 0.0.0.0
2011-01-07 12:01:45 us=650000 server_bridge_netmask = 0.0.0.0
2011-01-07 12:01:45 us=650011 server_bridge_pool_start = 0.0.0.0
2011-01-07 12:01:45 us=650021 server_bridge_pool_end = 0.0.0.0
2011-01-07 12:01:45 us=650031 ifconfig_pool_defined = DISABLED
2011-01-07 12:01:45 us=650042 ifconfig_pool_start = 0.0.0.0
2011-01-07 12:01:45 us=650052 ifconfig_pool_end = 0.0.0.0
2011-01-07 12:01:45 us=650063 ifconfig_pool_netmask = 0.0.0.0
2011-01-07 12:01:45 us=650072 ifconfig_pool_persist_filename = '[UNDEF]'
2011-01-07 12:01:45 us=650082 ifconfig_pool_persist_refresh_freq = 600
2011-01-07 12:01:45 us=650092 n_bcast_buf = 256
2011-01-07 12:01:45 us=650102 tcp_queue_limit = 64
2011-01-07 12:01:45 us=650111 real_hash_size = 256
2011-01-07 12:01:45 us=650121 virtual_hash_size = 256
2011-01-07 12:01:45 us=650130 client_connect_script = '[UNDEF]'
2011-01-07 12:01:45 us=650140 learn_address_script = '[UNDEF]'
2011-01-07 12:01:45 us=650150 client_disconnect_script = '[UNDEF]'
2011-01-07 12:01:45 us=650159 client_config_dir = '[UNDEF]'
2011-01-07 12:01:45 us=650169 ccd_exclusive = DISABLED
2011-01-07 12:01:45 us=650178 tmp_dir = '[UNDEF]'
2011-01-07 12:01:45 us=650188 push_ifconfig_defined = DISABLED
2011-01-07 12:01:45 us=650199 push_ifconfig_local = 0.0.0.0
2011-01-07 12:01:45 us=650209 push_ifconfig_remote_netmask = 0.0.0.0
2011-01-07 12:01:45 us=650219 enable_c2c = DISABLED
2011-01-07 12:01:45 us=650228 duplicate_cn = DISABLED
2011-01-07 12:01:45 us=650238 cf_max = 0
2011-01-07 12:01:45 us=650248 cf_per = 0
2011-01-07 12:01:45 us=650258 max_clients = 1024
2011-01-07 12:01:45 us=650267 max_routes_per_client = 256
2011-01-07 12:01:45 us=650277 auth_user_pass_verify_script = '[UNDEF]'
2011-01-07 12:01:45 us=650287 auth_user_pass_verify_script_via_file = DISABLED
2011-01-07 12:01:45 us=650297 ssl_flags = 0
2011-01-07 12:01:45 us=650306 port_share_host = '[UNDEF]'
2011-01-07 12:01:45 us=650316 port_share_port = 0
2011-01-07 12:01:45 us=650325 client = ENABLED
2011-01-07 12:01:45 us=650345 pull = ENABLED
2011-01-07 12:01:45 us=650355 auth_user_pass_file = '[UNDEF]'
2011-01-07 12:01:45 us=650370 OpenVPN 2.1.4 i386-apple-darwin10.5.0 [SSL] [LZO2] [PKCS11] built on Dec 9 2010
2011-01-07 12:01:45 us=650486 MANAGEMENT: TCP Socket listening on 127.0.0.1:1338
2011-01-07 12:01:45 us=651020 Need hold release from management interface, waiting...
2011-01-07 12:01:45 us=781977 MANAGEMENT: Client connected from 127.0.0.1:1338
2011-01-07 12:01:45 us=816175 MANAGEMENT: CMD 'pid'
2011-01-07 12:01:45 us=816410 MANAGEMENT: CMD 'state on'
2011-01-07 12:01:45 us=816456 MANAGEMENT: CMD 'state'
2011-01-07 12:01:45 us=816540 MANAGEMENT: CMD 'hold release'
2011-01-07 12:01:45 us=816790 WARNING: No server certificate verification method has been enabled. See http://openvpn.net/howto.html#mitm for more info.
2011-01-07 12:01:45 us=816804 NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
2011-01-07 12:01:45 us=817642 WARNING: file '/Users/iceberg/.keys/client.key' is group or others accessible
2011-01-07 12:01:45 us=818289 LZO compression initialized
2011-01-07 12:01:45 us=818498 Control Channel MTU parms [ L:1542 D:138 EF:38 EB:0 ET:0 EL:0 ]
2011-01-07 12:01:45 us=818563 Socket Buffers: R=[42080->65536] S=[9216->65536]
2011-01-07 12:01:45 us=818582 Data Channel MTU parms [ L:1542 D:1450 EF:42 EB:135 ET:0 EL:0 AF:3/1 ]
2011-01-07 12:01:45 us=818602 Local Options String: 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-client'
2011-01-07 12:01:45 us=818613 Expected Remote Options String: 'V4,dev-type tun,link-mtu 1542,tun-mtu 1500,proto UDPv4,comp-lzo,cipher BF-CBC,auth SHA1,keysize 128,key-method 2,tls-server'
2011-01-07 12:01:45 us=818634 Local Options hash (VER=V4): '41690919'
2011-01-07 12:01:45 us=818650 Expected Remote Options hash (VER=V4): '530fdded'
2011-01-07 12:01:45 us=818670 UDPv4 link local: [undef]
2011-01-07 12:01:45 us=818688 UDPv4 link remote: 64.141.147.212:1194
2011-01-07 12:01:45 us=818730 MANAGEMENT: >STATE:1294419705,WAIT,,,
2011-01-07 12:01:45 us=887123 MANAGEMENT: >STATE:1294419705,AUTH,,,
2011-01-07 12:01:45 us=887193 TLS: Initial packet from 64.141.147.212:1194, sid=385c481e 56f1200e
2011-01-07 12:01:45 *Tunnelblick: openvpnstart: /Applications/Tunnelblick.app/Contents/Resources/openvpn --cd /Users/iceberg/Library/Application Support/Tunnelblick/Configurations --daemon --management 127.0.0.1 1338 --config /Users/iceberg/Library/Application Support/Tunnelblick/Configurations/config.ovpn --log /tmp/tunnelblick/logs/-SUsers-Siceberg-SLibrary-SApplication Support-STunnelblick-SConfigurations-Sconfig.ovpn.1_0_0_0_49.1338.openvpn.log --management-query-passwords --management-hold --script-security 2 --up /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -m -w -d --down /Applications/Tunnelblick.app/Contents/Resources/client.down.tunnelblick.sh -m -w -d --up-restart
2011-01-07 12:01:46 us=428839 VERIFY OK: depth=1, /C=US/ST=IN/L=Marion/O=vpnserver/OU=vpnserver/CN=vpnserver/name=vpnserver/emailAddress=support@onbuso.net
2011-01-07 12:01:46 us=429813 VERIFY OK: depth=0, /C=US/ST=IN/L=Marion/O=vpnserver/OU=vpnserver/CN=server/name=vpnserver/emailAddress=support@onbuso.net
2011-01-07 12:01:47 us=516610 Data Channel Encrypt: Cipher 'BF-CBC' initialized with 128 bit key
2011-01-07 12:01:47 us=517022 Data Channel Encrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
2011-01-07 12:01:47 us=517108 Data Channel Decrypt: Cipher 'BF-CBC' initialized with 128 bit key
2011-01-07 12:01:47 us=517131 Data Channel Decrypt: Using 160 bit message hash 'SHA1' for HMAC authentication
2011-01-07 12:01:47 us=517187 Control Channel: TLSv1, cipher TLSv1/SSLv3 DHE-RSA-AES256-SHA, 2048 bit RSA
2011-01-07 12:01:47 us=517233 [server] Peer Connection Initiated with 64.141.147.212:1194
2011-01-07 12:01:48 us=574089 MANAGEMENT: >STATE:1294419708,GET_CONFIG,,,
2011-01-07 12:01:49 us=631117 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1)
2011-01-07 12:01:49 us=702525 PUSH: Received control message: 'PUSH_REPLY,route 10.2.2.0 255.255.255.0,route 10.8.0.0 255.255.255.0,route 10.8.0.1,topology net30,ping 10,ping-restart 120,ifconfig 10.8.0.6 10.8.0.5'
2011-01-07 12:01:49 us=702661 OPTIONS IMPORT: timers and/or timeouts modified
2011-01-07 12:01:49 us=702682 OPTIONS IMPORT: --ifconfig/up options modified
2011-01-07 12:01:49 us=702697 OPTIONS IMPORT: route options modified
2011-01-07 12:01:49 us=702853 ROUTE default_gateway=192.168.0.1
2011-01-07 12:01:49 us=703083 TUN/TAP device /dev/tun0 opened
2011-01-07 12:01:49 us=703118 MANAGEMENT: >STATE:1294419709,ASSIGN_IP,,10.8.0.6,
2011-01-07 12:01:49 us=703150 /sbin/ifconfig tun0 delete
ifconfig: ioctl (SIOCDIFADDR): Can't assign requested address
2011-01-07 12:01:49 us=707389 NOTE: Tried to delete pre-existing tun/tap instance -- No Problem if failure
2011-01-07 12:01:49 us=707461 /sbin/ifconfig tun0 10.8.0.6 10.8.0.5 mtu 1500 netmask 255.255.255.255 up
2011-01-07 12:01:49 us=710334 /Applications/Tunnelblick.app/Contents/Resources/client.up.tunnelblick.sh -m -w -d tun0 1500 1542 10.8.0.6 10.8.0.5 init
2011-01-07 12:01:49 us=770716 MANAGEMENT: >STATE:1294419709,ADD_ROUTES,,,
2011-01-07 12:01:49 us=770822 /sbin/route add -net 10.2.2.0 10.8.0.5 255.255.255.0
add net 10.2.2.0: gateway 10.8.0.5
2011-01-07 12:01:49 us=778994 /sbin/route add -net 10.8.0.0 10.8.0.5 255.255.255.0
add net 10.8.0.0: gateway 10.8.0.5
2011-01-07 12:01:49 us=787225 /sbin/route add -net 10.8.0.1 10.8.0.5 255.255.255.255
add net 10.8.0.1: gateway 10.8.0.5
2011-01-07 12:01:49 us=802545 Initialization Sequence Completed
2011-01-07 12:01:49 us=802721 MANAGEMENT: >STATE:1294419709,CONNECTED,SUCCESS,10.8.0.6,64.141.147.212
2011-01-07 12:01:49 *Tunnelblick client.up.tunnelblick.sh: No network configuration changes need to be made
2011-01-07 12:01:49 *Tunnelblick client.up.tunnelblick.sh: Will NOT monitor for other network configuration changes
2011-01-07 12:01:49 *Tunnelblick: Flushed the DNS cache