|
QuickStartGuide
Quick Start Guide
PLEASE discuss any problems on the Tunnelblick Discussion List. Take a look at What Tunnelblick Is if you aren't sure. This is a Quick Start Guide to Tunnelblick; for a more through and complete discussion of Tunnelblick see Using Tunnelblick. This document contains the following sections: Installing Tunnelblick and Getting it Set UpHere is what you need to get started using Tunnelblick:
To get started, double-click the disk image. A window will open. Double-click the Tunnelblick icon in the window to start the installation process. You will be asked if you want to install/reinstall/upgrade/downgrade Tunnelblick. Click the "Install" button to install Tunnelblick to your Applications folder. If you are reinstalling, upgrading, or downgrading, your current copy of Tunnelblick will be put in the Trash before it is replaced. After a few seconds, a new window will appear asking if you wish to launch Tunnelblick. Click the "Launch" button to launch Tunnelblick. If your computer is already running Tunnelblick, you will be asked if you wish to close all connections and quit the current copy. Click the button to do so. You will now see a window asking for an administrator username and password. Enter them and click "OK". You may see a window asking if you wish to check for updates automatically. Click a button to indicate your selection. When there are no configuration files in ~/Library/Application Support/Tunnelblick/Configurations (which is usually the case the first time Tunnelblick is run by each user), the "Welcome to Tunnelblick" window will appear. You have three choices:
Launching TunnelblickTo launch Tunnelblick after setting up configuration and other files, double-click "Launch Tunnelblick" in the Configurations folder, or double-click Tunnelblick in the Applications folder. Using TunnelblickOnce Tunnelblick has been launched, you control it from the Tunnelblick icon in the Status Bar at the top of your screen. The Tunnelblick icon is usually placed between the time and the Spotlight icon. When no VPN connection is active, the icon is dark, indicating a closed tunnel. If you click on the icon, you'll see a drop down menu. The menu has
If you click on "Details…", a new window will appear with a tab for each configuration. Each tab includes preferences, the OpenVPN log, and several buttons. You may use the standard keyboard shortcuts in the "Details…" window: Command-C, Command-X, and Command-V for copy, cut, and paste; and Command-A, Command-M, Command-W, and Command-Q to select all the text in the log that is currently being displayed, minimize the window to the dock, close the window, and quit the program. Connecting to a VPNTo connect to a VPN, either
To illustrate the connection being established, three dots will appear in the menu item, and the Tunnelblick icon will darken and lighten repeatedly. If the connection is successfully established, the Tunnelblick icon will change to show an open tunnel, and the "Connect..." menu item for the connection will change to "Disconnect...". Depending on your setup, you may be asked for a passphrase or username/password combination. You can save your passphrase or password in Apple's Keychain by checking the appropriate checkbox. The connection will be active as long as you do not end it or log out. Putting your computer to sleep will close the connection but upon waking up from sleep Tunnelblick will attempt to reestablish the connection. Disconnecting from a VPNTo disconnect from a VPN, either
It usually takes a couple of seconds to disconnect from a VPN. Quitting TunnelblickYou can quit Tunnelblick by:
Tunnelblick will close all connections before it quits. If you don't quit Tunnelblick before logging out, it will be started automatically upon login. Don't confuse this automatic launch of Tunnelblick upon login with the "automatically connect on launch” option, which causes a connection to be established when Tunnelblick is started. PreferencesThe "Options…" submenu allows you to control several preferences. Click on one to change its status from checked to unchecked and vice-versa:
The "Details…" window allows you to control several preferences for each configuration separately:
For more details on "Set nameserver" see the following section. There are many other preferences that control Tunnelblick's behavior. See Preferences. The Set Nameserver Check Box and DNS and WINS SettingsIf you are using DHCP, wish to use DNS and WINS servers at the far end of the tunnel when connected, and the VPN server you are connecting to "pushes" DNS and WINS settings to your client, put a check in the "Set nameserver" checkbox. (This is the situation for most users.) If you are using DHCP, wish to use your original DNS and WINS servers when connected, and the VPN server you are connecting to does not "push" DNS or WINS settings to your client, un-check the "Set nameserver" checkbox. If you are using manual settings, different versions of OS X behave differently. This is due to a change in network behavior in Snow Leopard and is beyond the scope of this project to fix. If you're using Leopard (10.5) or Tiger (10.4), then it is possible to use the VPN-server-supplied DNS and WINS settings in addition to your manual settings by checking the "Set nameserver" box. However, your manual settings will always take precedence over any VPN server-supplied settings. If "Set nameserver" is un-checked, you will continue to use only your manually-configured settings and any VPN server-supplied settings will be ignored. If you are using Snow Leopard (10.6), then your manually-configured DNS and WINS settings will always be used, and no aggregation of configurations will be performed.
If your situation is not described above (e.g., if you use manual DNS settings and wish to use DNS servers at the far end of a tunnel when connected, or you wish to use the OS X ability to use different nameservers for different domains), you must create your own up/down scripts and un-check the "Set nameserver" checkbox. What Tunnelblick Is
VPNs are primarily used two ways, or sometimes both ways simultaneously: In addition to Tunnelblick, you need access to a VPN server. Your company may provide one, or you can obtain VPN service from any of several VPN service providers, or you can use another one of your computers or a router to act as a VPN server.
It runs on OS X Tiger (10.4), Leopard (10.5), and Snow Leopard (10.6). It comes as a ready-to-use Universal application with all necessary binaries and drivers (including OpenVPN and tun/tap) included. No additional installation is necessary -- just add your configuration and encryption information. Tunnelblick is free software licensed under the GNU General Public License (GPL) Version 2. For more information, including wikis and a discussion group, see the Tunnelblick home page. Document History
PLEASE USE THE TUNNELBLICK DISCUSSION GROUP FOR COMMENTS OR QUESTIONS | |