• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Tunnelblick 3.7.5

Scheduled Pinned Locked Moved OpenVPN
4 Posts 4 Posters 1.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R
    rampplane
    last edited by Mar 6, 2018, 3:13 PM

    Today, I applied the latest Tunnelblick security update (3.7.5 build 5010) on my Mac High Sierra. After doing so, I reconnected to my pfsense box (2.4.2-RELEASE-p1), and got the following message from Tunnelblick:
    Warning: This VPN may not connect in the future.
    The OpenVPN configuration file for 'pfSense-UDP4-1194-vpnuser-config' contains these OpenVPN options:
    'comp-lzo' was deprecated in OpenVPN 2.4 and removed in OpenVPN 2.5
    You should update the configuration so it can be used with modern versions of OpenVPN.
    Tunnelblick will use OpenVPN 2.4.4 - OpenSSL v1.0.2n to connect this configuration.
    However, you will not be able to connect to this VPN with future versions of Tunnelblick that do not include a version of OpenVPN that accepts the options.

    I downloaded a new client config from pfsense, and applied it (there were some slightly different settings in the newest version) the same result.

    Just thought I should bring it up, in case it is important!

    1 Reply Last reply Reply Quote 0
    • N
      necron
      last edited by Mar 21, 2018, 9:32 AM

      Just a bump to get some attention and a question.

      If the option comp-lzo is to be removed from the clients config, how much would this affect the tunnel?
      With the current high bandwidth available, is this still an issue?

      1 Reply Last reply Reply Quote 0
      • D
        DrHorrible
        last edited by Mar 21, 2018, 5:11 PM

        Hi necron,

        While I do not have a solution to this problem, I can confirm that I also have received this message. I would hope that anyone with knowledge of this could shed more light.

        1 Reply Last reply Reply Quote 0
        • S
          sco01
          last edited by Mar 22, 2018, 9:31 AM

          Same thing here but with a different option:

          'ns-cert-type' was deprecated in OpenVPN 2.4 and removed in OpenVPN 2.5

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received