<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Tunnelblick</title>
	<atom:link href="http://erdelynet.com/tech/mac-os-x/tunnelblick/feed/" rel="self" type="application/rss+xml" />
	<link>http://erdelynet.com/tech/mac-os-x/tunnelblick/</link>
	<description>Mike Erdely's website (still faster than Scott's blog)</description>
	<lastBuildDate>Wed, 10 Feb 2010 22:55:02 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Zvi</title>
		<link>http://erdelynet.com/tech/mac-os-x/tunnelblick/comment-page-1/#comment-7019</link>
		<dc:creator>Zvi</dc:creator>
		<pubDate>Sat, 26 Apr 2008 00:16:09 +0000</pubDate>
		<guid isPermaLink="false">http://erdelynet.com/2006/04/16/mac-os-x/tunnelblick/#comment-7019</guid>
		<description>Newbie question.... Trying to run Tunnelblick on MacBook Pro Leopard. Copied the config files that worked on Windows. Do I need to do something equivalent to creating a TAPI adapter (whatever that means) like I did on Windows and if so how?  So far I just get these errors in the Tunnelblick log.  Any help appreciated please?  Are there good instructions anywhere or a more organized discussion group besides this long thread?  Thanks!


Sat 04/26/08 03:10 AM: IMPORTANT: OpenVPN&#039;s default port number is now 1194
Sat 04/26/08 03:10 AM: WARNING: No server certificate verification method has been enabled.  See http://openvpn.net/howto.html#mitm for more info.
Sat 04/26/08 03:10 AM: Cannot load certificate file client.crt: error:02001002:system library:fopen:No such file or directory: error:20074002:BIO routines:FILE_CTRL:system lib: error:140AD002:SSL routines:SSL_CTX_use_certificate_file:system lib</description>
		<content:encoded><![CDATA[<p>Newbie question&#8230;. Trying to run Tunnelblick on MacBook Pro Leopard. Copied the config files that worked on Windows. Do I need to do something equivalent to creating a TAPI adapter (whatever that means) like I did on Windows and if so how?  So far I just get these errors in the Tunnelblick log.  Any help appreciated please?  Are there good instructions anywhere or a more organized discussion group besides this long thread?  Thanks!</p>
<p>Sat 04/26/08 03:10 AM: IMPORTANT: OpenVPN&#8217;s default port number is now 1194<br />
Sat 04/26/08 03:10 AM: WARNING: No server certificate verification method has been enabled.  See <a href="http://openvpn.net/howto.html#mitm" rel="nofollow">http://openvpn.net/howto.html#mitm</a> for more info.<br />
Sat 04/26/08 03:10 AM: Cannot load certificate file client.crt: error:02001002:system library:fopen:No such file or directory: error:20074002:BIO routines:FILE_CTRL:system lib: error:140AD002:SSL routines:SSL_CTX_use_certificate_file:system lib</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wioota</title>
		<link>http://erdelynet.com/tech/mac-os-x/tunnelblick/comment-page-1/#comment-6865</link>
		<dc:creator>wioota</dc:creator>
		<pubDate>Thu, 17 Apr 2008 10:16:53 +0000</pubDate>
		<guid isPermaLink="false">http://erdelynet.com/2006/04/16/mac-os-x/tunnelblick/#comment-6865</guid>
		<description>I am also affected with this problem - and after much battling to get Tunnelblick working under 10.5.2 at the office I find I am still caught short when accessing from home through my wrt54g.

The two previous posts seem to describe the situation exactly.</description>
		<content:encoded><![CDATA[<p>I am also affected with this problem &#8211; and after much battling to get Tunnelblick working under 10.5.2 at the office I find I am still caught short when accessing from home through my wrt54g.</p>
<p>The two previous posts seem to describe the situation exactly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nicolas</title>
		<link>http://erdelynet.com/tech/mac-os-x/tunnelblick/comment-page-1/#comment-6544</link>
		<dc:creator>Nicolas</dc:creator>
		<pubDate>Wed, 26 Mar 2008 18:04:21 +0000</pubDate>
		<guid isPermaLink="false">http://erdelynet.com/2006/04/16/mac-os-x/tunnelblick/#comment-6544</guid>
		<description>@Gilles: I think I have exactly the same problem. Tunnelbllick reports &quot;Initialization Sequence Completed&quot;, but after that, I&#039;m unable to connect to the windows server at work. It&#039;s not a problem of the server, as I don&#039;t have any problem connecting to it when I&#039;m at the office. Have you found a solution?
My VPN used to work fine last january, so I think it may be an issue with 10.5.2.</description>
		<content:encoded><![CDATA[<p>@Gilles: I think I have exactly the same problem. Tunnelbllick reports &#8220;Initialization Sequence Completed&#8221;, but after that, I&#8217;m unable to connect to the windows server at work. It&#8217;s not a problem of the server, as I don&#8217;t have any problem connecting to it when I&#8217;m at the office. Have you found a solution?<br />
My VPN used to work fine last january, so I think it may be an issue with 10.5.2.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gilles</title>
		<link>http://erdelynet.com/tech/mac-os-x/tunnelblick/comment-page-1/#comment-6278</link>
		<dc:creator>Gilles</dc:creator>
		<pubDate>Wed, 05 Mar 2008 19:15:10 +0000</pubDate>
		<guid isPermaLink="false">http://erdelynet.com/2006/04/16/mac-os-x/tunnelblick/#comment-6278</guid>
		<description>Hi,
Sounds like I&#039;m not the only one facing problems with openvpn on leopard.. spent hours trying to figure out how to push all the traffic through the VPN tunnel, so maybe someone here can give me a tip?

I&#039;m using openVPN in bridged mode - my home router (myISP_IP/192.168.1.1) runs the server and allocates an IP to connecting clients (192.168.1.x, this works fine with my PDAphone with OpenVPN for windows mobile and on my previous XP laptop).

On my MacBook Pro, I have compiled OpenVPN and the tunnel is properly created with no warning. The tap0 if gets an IP as it&#039;s supposed to, I can ping the gateway but the rest of the traffic goes through my company&#039;s gateway...

The server looks like this:

openvpn --dev tap0 --secret /tmp/static.key --comp-lzo --port 443 --proto tcp-server --verb 3 --log /tmp
/openvpn.log --daemon

and the client on my mac:

remote myISP_IP # IP 
route-delay 3
route-gateway 192.168.1.1
redirect-gateway def1
port 443
dev tap
secret static.key
proto tcp-client
comp-lzo
up ./tap-up-down.sh
down ./tap-up-down.sh

The client log says:
...
Wed Mar  5 19:57:23 2008 Peer Connection Initiated with myIP:443
add net myISP_IP: gateway myCompany_IP
add net 0.0.0.0: gateway 192.168.1.1
add net 128.0.0.0: gateway 192.168.1.1
Wed Mar  5 19:57:26 2008 Initialization Sequence Completed


but no way... notice that I used both route_gateway and redirect_gateway is an apparently appropriate way, but the default routes are not changed... I&#039;m losing network connection and cannot even see my routing tables: netstat -r hangs or takes ages and confirms default still not 192.168.1.1)

If someone sees the problem... I&#039;d be really glad to fix this!

Cheers,

Gilles</description>
		<content:encoded><![CDATA[<p>Hi,<br />
Sounds like I&#8217;m not the only one facing problems with openvpn on leopard.. spent hours trying to figure out how to push all the traffic through the VPN tunnel, so maybe someone here can give me a tip?</p>
<p>I&#8217;m using openVPN in bridged mode &#8211; my home router (myISP_IP/192.168.1.1) runs the server and allocates an IP to connecting clients (192.168.1.x, this works fine with my PDAphone with OpenVPN for windows mobile and on my previous XP laptop).</p>
<p>On my MacBook Pro, I have compiled OpenVPN and the tunnel is properly created with no warning. The tap0 if gets an IP as it&#8217;s supposed to, I can ping the gateway but the rest of the traffic goes through my company&#8217;s gateway&#8230;</p>
<p>The server looks like this:</p>
<p>openvpn &#8211;dev tap0 &#8211;secret /tmp/static.key &#8211;comp-lzo &#8211;port 443 &#8211;proto tcp-server &#8211;verb 3 &#8211;log /tmp<br />
/openvpn.log &#8211;daemon</p>
<p>and the client on my mac:</p>
<p>remote myISP_IP # IP<br />
route-delay 3<br />
route-gateway 192.168.1.1<br />
redirect-gateway def1<br />
port 443<br />
dev tap<br />
secret static.key<br />
proto tcp-client<br />
comp-lzo<br />
up ./tap-up-down.sh<br />
down ./tap-up-down.sh</p>
<p>The client log says:<br />
&#8230;<br />
Wed Mar  5 19:57:23 2008 Peer Connection Initiated with myIP:443<br />
add net myISP_IP: gateway myCompany_IP<br />
add net 0.0.0.0: gateway 192.168.1.1<br />
add net 128.0.0.0: gateway 192.168.1.1<br />
Wed Mar  5 19:57:26 2008 Initialization Sequence Completed</p>
<p>but no way&#8230; notice that I used both route_gateway and redirect_gateway is an apparently appropriate way, but the default routes are not changed&#8230; I&#8217;m losing network connection and cannot even see my routing tables: netstat -r hangs or takes ages and confirms default still not 192.168.1.1)</p>
<p>If someone sees the problem&#8230; I&#8217;d be really glad to fix this!</p>
<p>Cheers,</p>
<p>Gilles</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steve</title>
		<link>http://erdelynet.com/tech/mac-os-x/tunnelblick/comment-page-1/#comment-2520</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Mon, 19 Mar 2007 03:49:41 +0000</pubDate>
		<guid isPermaLink="false">http://erdelynet.com/2006/04/16/mac-os-x/tunnelblick/#comment-2520</guid>
		<description>i meant tap0, not tun0...</description>
		<content:encoded><![CDATA[<p>i meant tap0, not tun0&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steve</title>
		<link>http://erdelynet.com/tech/mac-os-x/tunnelblick/comment-page-1/#comment-2519</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Mon, 19 Mar 2007 03:48:27 +0000</pubDate>
		<guid isPermaLink="false">http://erdelynet.com/2006/04/16/mac-os-x/tunnelblick/#comment-2519</guid>
		<description>my understanding is that redirect-gateway is a server option or a client option, either way, which makes it very flexible and client selectable.

if that wasnt true, then i like your idea of 2 servers as a work around.

i&#039;m actually much closer now to getting it to work on the client.
my problem was that in the client settings i only had:

redirect-gateway def1  #def1 makes it temporary

instead of

route-gateway 10.21.21.1
redirect-gateway def1  #def1 makes it temporary

I didn&#039;t know you had to hardcode the route-gateway in there.
perhaps if i did a push &quot;route-gateway 10.21.21.1&quot; from the server.
but last time i pushed both the gateway and the dns from the dd-wrt openvpn server the openvpn process would die.

BEFORE netstat -r reveals:
default            gtwy.mydomain.net   UGSc       19      214    en1

AFTER: netstat -r reveals:
0/1                10.23.23.1         UGSc        5       22    en1
default            gtwy.mydomain.net   UGSc        2      145    en1

as you can see, the problem is the command is adding the gateway to en1 not tap0 as it should.  i need to find a way to give the redirect-gateway command a parameter of tun0

btw, i had to use a tap-up.sh script with Tunnelblick to get the tunnel to work at all:
http://www.dd-wrt.com/phpBB2/viewtopic.php?t=5058&amp;highlight=openvpn+mac+clients

#!/bin/bash
ipconfig set tap0 DHCP</description>
		<content:encoded><![CDATA[<p>my understanding is that redirect-gateway is a server option or a client option, either way, which makes it very flexible and client selectable.</p>
<p>if that wasnt true, then i like your idea of 2 servers as a work around.</p>
<p>i&#8217;m actually much closer now to getting it to work on the client.<br />
my problem was that in the client settings i only had:</p>
<p>redirect-gateway def1  #def1 makes it temporary</p>
<p>instead of</p>
<p>route-gateway 10.21.21.1<br />
redirect-gateway def1  #def1 makes it temporary</p>
<p>I didn&#8217;t know you had to hardcode the route-gateway in there.<br />
perhaps if i did a push &#8220;route-gateway 10.21.21.1&#8243; from the server.<br />
but last time i pushed both the gateway and the dns from the dd-wrt openvpn server the openvpn process would die.</p>
<p>BEFORE netstat -r reveals:<br />
default            gtwy.mydomain.net   UGSc       19      214    en1</p>
<p>AFTER: netstat -r reveals:<br />
0/1                10.23.23.1         UGSc        5       22    en1<br />
default            gtwy.mydomain.net   UGSc        2      145    en1</p>
<p>as you can see, the problem is the command is adding the gateway to en1 not tap0 as it should.  i need to find a way to give the redirect-gateway command a parameter of tun0</p>
<p>btw, i had to use a tap-up.sh script with Tunnelblick to get the tunnel to work at all:<br />
<a href="http://www.dd-wrt.com/phpBB2/viewtopic.php?t=5058&amp;highlight=openvpn+mac+clients" rel="nofollow">http://www.dd-wrt.com/phpBB2/viewtopic.php?t=5058&amp;highlight=openvpn+mac+clients</a></p>
<p>#!/bin/bash<br />
ipconfig set tap0 DHCP</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mike</title>
		<link>http://erdelynet.com/tech/mac-os-x/tunnelblick/comment-page-1/#comment-2465</link>
		<dc:creator>mike</dc:creator>
		<pubDate>Mon, 12 Mar 2007 14:07:26 +0000</pubDate>
		<guid isPermaLink="false">http://erdelynet.com/2006/04/16/mac-os-x/tunnelblick/#comment-2465</guid>
		<description>&quot;redirect-gateway&quot; is a server side setting.  Not a client side setting.

For my home network, I have two instances of openvpn running.  One for just securely connecting to home resources and the second for routing all of my network traffic through my home network with redirect-gateway.  One is on port 1194 and the other is on 1195.  I have two configuration files so Tunnelblick gives me two options.</description>
		<content:encoded><![CDATA[<p>&#8220;redirect-gateway&#8221; is a server side setting.  Not a client side setting.</p>
<p>For my home network, I have two instances of openvpn running.  One for just securely connecting to home resources and the second for routing all of my network traffic through my home network with redirect-gateway.  One is on port 1194 and the other is on 1195.  I have two configuration files so Tunnelblick gives me two options.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: steve</title>
		<link>http://erdelynet.com/tech/mac-os-x/tunnelblick/comment-page-1/#comment-2461</link>
		<dc:creator>steve</dc:creator>
		<pubDate>Mon, 12 Mar 2007 01:33:23 +0000</pubDate>
		<guid isPermaLink="false">http://erdelynet.com/2006/04/16/mac-os-x/tunnelblick/#comment-2461</guid>
		<description>&gt;Posted May 8, 2006 @ 11:16 am EDT 
&gt; By mike
&gt;
&gt; This is not a Tunnelblick issue. Itâ€™s an OpenVPN issue. Look at the â€˜push â€œredirect-gatewayâ€â€˜ option on the server.

mike we meet again for Tunnelblick questions!

have you ever gotten Tunnelblick to pass the gateway properly with this option?

i have been trying to do just that... push all traffic through the VPN with redirect-gateway directtive on the client.

Tunnelblick just says  
NOTE: unable to redirect default gateway -- VPN gateway parameter (--route-gateway or --ifconfig) is missing

i was able to get the DNS server passed correctly as per my other note referencing this thread...

http://openvpn.net/archive/openvpn-users/2006-10/msg00120.html</description>
		<content:encoded><![CDATA[<p>&gt;Posted May 8, 2006 @ 11:16 am EDT<br />
&gt; By mike<br />
&gt;<br />
&gt; This is not a Tunnelblick issue. Itâ€™s an OpenVPN issue. Look at the â€˜push â€œredirect-gatewayâ€â€˜ option on the server.</p>
<p>mike we meet again for Tunnelblick questions!</p>
<p>have you ever gotten Tunnelblick to pass the gateway properly with this option?</p>
<p>i have been trying to do just that&#8230; push all traffic through the VPN with redirect-gateway directtive on the client.</p>
<p>Tunnelblick just says<br />
NOTE: unable to redirect default gateway &#8212; VPN gateway parameter (&#8211;route-gateway or &#8211;ifconfig) is missing</p>
<p>i was able to get the DNS server passed correctly as per my other note referencing this thread&#8230;</p>
<p><a href="http://openvpn.net/archive/openvpn-users/2006-10/msg00120.html" rel="nofollow">http://openvpn.net/archive/openvpn-users/2006-10/msg00120.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: perkypat</title>
		<link>http://erdelynet.com/tech/mac-os-x/tunnelblick/comment-page-1/#comment-2107</link>
		<dc:creator>perkypat</dc:creator>
		<pubDate>Sat, 10 Feb 2007 09:09:52 +0000</pubDate>
		<guid isPermaLink="false">http://erdelynet.com/2006/04/16/mac-os-x/tunnelblick/#comment-2107</guid>
		<description>I have been trying to VPN to my office for ages, havn&#039;t got it working! Using OS X 10.4 on an intel macbook. Tunnelblick seems to connect okay, but when i try and ssh in, I get the error: No address associated with nodemname.

I typed ifconfig, and tried to ping the tun0 addresses given, no joy. I also tried manually adding the nameserver to /etc/resolve/conf. Any ideas????</description>
		<content:encoded><![CDATA[<p>I have been trying to VPN to my office for ages, havn&#8217;t got it working! Using OS X 10.4 on an intel macbook. Tunnelblick seems to connect okay, but when i try and ssh in, I get the error: No address associated with nodemname.</p>
<p>I typed ifconfig, and tried to ping the tun0 addresses given, no joy. I also tried manually adding the nameserver to /etc/resolve/conf. Any ideas????</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DAnny</title>
		<link>http://erdelynet.com/tech/mac-os-x/tunnelblick/comment-page-1/#comment-815</link>
		<dc:creator>DAnny</dc:creator>
		<pubDate>Tue, 28 Nov 2006 21:28:41 +0000</pubDate>
		<guid isPermaLink="false">http://erdelynet.com/2006/04/16/mac-os-x/tunnelblick/#comment-815</guid>
		<description>I get the following error:
OpenVPN 2.0.5 i686-apple-darwin8.3.1 [SSL] [LZO] built on Dec  4 2005
Nov 28 21:20:53 MacBookPro openvpn[283]: Footer text not found in file &#039;/etc/openvpn/static.key&#039; (256/128/256 bytes found/min/max)
Nov 28 21:20:53 MacBookPro openvpn[283]: Exiting

My static.key is at the specified location. Any suggestions?</description>
		<content:encoded><![CDATA[<p>I get the following error:<br />
OpenVPN 2.0.5 i686-apple-darwin8.3.1 [SSL] [LZO] built on Dec  4 2005<br />
Nov 28 21:20:53 MacBookPro openvpn[283]: Footer text not found in file &#8216;/etc/openvpn/static.key&#8217; (256/128/256 bytes found/min/max)<br />
Nov 28 21:20:53 MacBookPro openvpn[283]: Exiting</p>
<p>My static.key is at the specified location. Any suggestions?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
