1.13 DNS resolution fails

On a Win 10 system that was working fine, updated to 1.13. VPN connects fine. Once connected, dns names for the remote LAN will not resolve. I can ping remote LAN IPs successfully. I can start nslookup, tell it to use a remote LAN DNS server using that server’s IP, and nslookup will resolve. In ipconfig /all I see no DNS info for the connection on the local system - no connection-specific DNS suffix search list, no DNS Servers. I do see this info on a 1.12 PC when connected.
Again - no changes to the problem PC other than upgrading from 1.12.1 to 1.13.

Hi DennisT,

Could you please post (or email to us) the details listed in the following article and we can see what is going on for you:

Regards,
Aaron

#-- Config Auto Generated By Viscosity --#

#viscosity protocol openvpn
#viscosity startonopen false
#viscosity dhcp true
#viscosity dnssupport true
#viscosity name “SHHM TCP”
#viscosity autoreconnect false
#viscosity dns automatic
#viscosity usepeerdns true
#viscosity manageadapter true
remote 135.84.102.210 1195 tcp4-client
nobind
dev tun
persist-tun
persist-key
pull
tls-client
ca ca.crt
cert cert.crt
key key.key
remote-cert-tls server
verify-x509-name shhm.net name
resolv-retry infinite
dev-node {05A8EB81-A488-4FBD-A676-268850116166}
auth SHA256
data-ciphers-fallback AES-256-CBC
data-ciphers CHACHA20-POLY1305:AES-256-GCM:AES-128-GCM:AES-256-CBC

And the log:

Jul 12 7:04:06 PM: State changed to Connecting
Jul 12 7:04:06 PM: Viscosity Windows 1.13 (1877)
Jul 12 7:04:06 PM: Running on Windows 10 2009 (19045) 64 bit
Jul 12 7:04:06 PM: Running on .NET Framework Version 4.8.09037.533325
Jul 12 7:04:06 PM: Checking reachability status of connection…
Jul 12 7:04:06 PM: Connection is reachable. Starting connection attempt.
Jul 12 7:04:07 PM: Interface Type: ViscTunTap
Jul 12 7:04:07 PM: Bringing up interface…
Jul 12 7:04:07 PM: OpenVPN 2.6.21 Windows [SSL (OpenSSL)] [LZO] [LZ4] [AEAD]
Jul 12 7:04:07 PM: library versions: OpenSSL 3.5.7 9 Jun 2026, LZO 2.10
Jul 12 7:04:07 PM: Virtual Adapter Version: 1.1.1.1036
Jul 12 7:04:07 PM: Valid endpoint found: 135.84.102.210:1195:tcp4-client
Jul 12 7:04:08 PM: TCP/UDP: Preserving recently used remote address: [AF_INET]135.84.102.210:1195
Jul 12 7:04:08 PM: Attempting to establish TCP connection with [AF_INET]135.84.102.210:1195
Jul 12 7:04:08 PM: TCP connection established with [AF_INET]135.84.102.210:1195
Jul 12 7:04:08 PM: TCPv4_CLIENT link local: (not bound)
Jul 12 7:04:08 PM: TCPv4_CLIENT link remote: [AF_INET]135.84.102.210:1195
Jul 12 7:04:08 PM: State changed to Authenticating
Jul 12 7:04:08 PM: [shhm.net] Peer Connection Initiated with [AF_INET]135.84.102.210:1195
Jul 12 7:04:08 PM: State changed to Connecting
Jul 12 7:04:09 PM: Awaiting adapter to come up…
Jul 12 7:04:11 PM: TAP-WIN32 device [SHHM TCP] opened: \?\root#net#0006#{adda4c48-c32e-4ef6-9602-b3252f082583}, index: 2
Jul 12 7:04:11 PM: WARNING: Failed to get IPv6 interface information for MTU. This warning can be ignored if this stack is disabled. Element not found
Jul 12 7:04:11 PM: Waiting for DNS Setup to complete…
Jul 12 7:04:11 PM: Successful ARP Flush on interface [2] {05A8EB81-A488-4FBD-A676-268850116166}
Jul 12 7:04:15 PM: Initialization Sequence Completed
Jul 12 7:04:15 PM: DNS set to Split, Proxy failed to start. Please check Event Viewer for more information.
Jul 12 7:04:15 PM: State changed to Connected
Jul 12 7:06:58 PM: State changed to Disconnecting (Manual)
Jul 12 7:06:58 PM: SIGTERM[hard,] received, process exiting
Jul 12 7:06:59 PM: OpenVPN has exited. Exitcode = -1
Jul 12 7:06:59 PM: State changed to Disconnected
Jul 12 7:07:22 PM: State changed to Connecting
Jul 12 7:07:22 PM: Viscosity Windows 1.13 (1877)
Jul 12 7:07:22 PM: Running on Windows 10 2009 (19045) 64 bit
Jul 12 7:07:22 PM: Running on .NET Framework Version 4.8.09037.533325
Jul 12 7:07:22 PM: Checking reachability status of connection…
Jul 12 7:07:22 PM: Connection is reachable. Starting connection attempt.
Jul 12 7:07:22 PM: Interface Type: ViscTunTap
Jul 12 7:07:22 PM: Bringing up interface…
Jul 12 7:07:22 PM: Current Parameter Settings:
Jul 12 7:07:22 PM: config = ‘stdin’
Jul 12 7:07:22 PM: mode = 0
Jul 12 7:07:22 PM: show_ciphers = DISABLED
Jul 12 7:07:22 PM: show_digests = DISABLED
Jul 12 7:07:22 PM: show_engines = DISABLED
Jul 12 7:07:22 PM: genkey = DISABLED
Jul 12 7:07:22 PM: genkey_filename = ‘[UNDEF]’
Jul 12 7:07:22 PM: key_pass_file = ‘[UNDEF]’
Jul 12 7:07:22 PM: show_tls_ciphers = DISABLED
Jul 12 7:07:22 PM: connect_retry_max = 0
Jul 12 7:07:22 PM: Connection profiles [0]:
Jul 12 7:07:22 PM: proto = tcp4-client
Jul 12 7:07:22 PM: local = ‘[UNDEF]’
Jul 12 7:07:22 PM: local_port = ‘[UNDEF]’
Jul 12 7:07:22 PM: remote = ‘135.84.102.210’
Jul 12 7:07:22 PM: remote_port = ‘1195’
Jul 12 7:07:22 PM: remote_float = DISABLED
Jul 12 7:07:22 PM: bind_defined = DISABLED
Jul 12 7:07:22 PM: bind_local = DISABLED
Jul 12 7:07:22 PM: bind_ipv6_only = DISABLED
Jul 12 7:07:22 PM: connect_retry_seconds = 1
Jul 12 7:07:22 PM: connect_timeout = 120
Jul 12 7:07:22 PM: socks_proxy_server = ‘[UNDEF]’
Jul 12 7:07:22 PM: socks_proxy_port = ‘[UNDEF]’
Jul 12 7:07:22 PM: tun_mtu = 1500
Jul 12 7:07:22 PM: tun_mtu_defined = ENABLED
Jul 12 7:07:22 PM: link_mtu = 1500
Jul 12 7:07:22 PM: link_mtu_defined = DISABLED
Jul 12 7:07:22 PM: tun_mtu_extra = 0
Jul 12 7:07:22 PM: tun_mtu_extra_defined = DISABLED
Jul 12 7:07:22 PM: tls_mtu = 1250
Jul 12 7:07:22 PM: mtu_discover_type = -1
Jul 12 7:07:22 PM: NOTE: --mute triggered…
Jul 12 7:07:22 PM: 221 variation(s) on previous 100 message(s) suppressed by --mute
Jul 12 7:07:22 PM: OpenVPN 2.6.21 Windows [SSL (OpenSSL)] [LZO] [LZ4] [AEAD]
Jul 12 7:07:22 PM: library versions: OpenSSL 3.5.7 9 Jun 2026, LZO 2.10
Jul 12 7:07:22 PM: Virtual Adapter Version: 1.1.1.1036
Jul 12 7:07:22 PM: Valid endpoint found: 135.84.102.210:1195:tcp4-client
Jul 12 7:07:23 PM: Control Channel MTU parms [ mss_fix:0 max_frag:0 tun_mtu:1250 tun_max_mtu:0 headroom:126 payload:1600 tailroom:126 ET:0 ]
Jul 12 7:07:23 PM: Data Channel MTU parms [ mss_fix:0 max_frag:0 tun_mtu:1500 tun_max_mtu:1600 headroom:136 payload:1768 tailroom:562 ET:0 ]
Jul 12 7:07:23 PM: TCP/UDP: Preserving recently used remote address: [AF_INET]135.84.102.210:1195
Jul 12 7:07:23 PM: Socket Buffers: R=[65536->65536] S=[65536->65536]
Jul 12 7:07:23 PM: Attempting to establish TCP connection with [AF_INET]135.84.102.210:1195
Jul 12 7:07:23 PM: TCP connection established with [AF_INET]135.84.102.210:1195
Jul 12 7:07:23 PM: TCPv4_CLIENT link local: (not bound)
Jul 12 7:07:23 PM: TCPv4_CLIENT link remote: [AF_INET]135.84.102.210:1195
Jul 12 7:07:23 PM: State changed to Authenticating
Jul 12 7:07:23 PM: TLS: Initial packet from [AF_INET]135.84.102.210:1195, sid=0286588d 5ab484f3
Jul 12 7:07:23 PM: VERIFY OK: depth=1, CN=internal-ca, C=US, ST=CA, L=San Jose, O=SHHM
Jul 12 7:07:23 PM: VERIFY KU OK
Jul 12 7:07:23 PM: Validating certificate extended key usage
Jul 12 7:07:23 PM: ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Jul 12 7:07:23 PM: VERIFY EKU OK
Jul 12 7:07:23 PM: VERIFY X509NAME OK: CN=shhm.net, C=US, ST=CA, L=San Jose, O=SHHM
Jul 12 7:07:23 PM: VERIFY OK: depth=0, CN=shhm.net, C=US, ST=CA, L=San Jose, O=SHHM
Jul 12 7:07:23 PM: Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 2048 bits RSA, signature: RSA-SHA256, peer temporary key: 253 bits X25519
Jul 12 7:07:23 PM: [shhm.net] Peer Connection Initiated with [AF_INET]135.84.102.210:1195
Jul 12 7:07:23 PM: TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1
Jul 12 7:07:23 PM: TLS: tls_multi_process: initial untrusted session promoted to trusted
Jul 12 7:07:23 PM: State changed to Connecting
Jul 12 7:07:23 PM: SENT CONTROL [shhm.net]: ‘PUSH_REQUEST’ (status=1)
Jul 12 7:07:24 PM: SENT CONTROL [shhm.net]: ‘PUSH_REQUEST’ (status=1)
Jul 12 7:07:24 PM: PUSH: Received control message: ‘PUSH_REPLY,route 10.3.1.0 255.255.255.0,dhcp-option DOMAIN shhm.net,dhcp-option DNS 10.3.1.12,dhcp-option DNS 10.3.1.6,dhcp-option DNS 10.3.1.3,register-dns,route-gateway 10.13.2.1,topology subnet,ping 10,ping-restart 60,ifconfig 10.13.2.2 255.255.255.0,peer-id 0,cipher CHACHA20-POLY1305,protocol-flags cc-exit tls-ekm dyn-tls-crypt,tun-mtu 1500’
Jul 12 7:07:24 PM: OPTIONS IMPORT: --ifconfig/up options modified
Jul 12 7:07:24 PM: OPTIONS IMPORT: route options modified
Jul 12 7:07:24 PM: OPTIONS IMPORT: route-related options modified
Jul 12 7:07:24 PM: OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Jul 12 7:07:24 PM: OPTIONS IMPORT: tun-mtu set to 1500
Jul 12 7:07:24 PM: interactive service msg_channel=0
Jul 12 7:07:24 PM: ROUTE_GATEWAY 10.2.1.254/255.255.255.0 I=21 HWADDR=c0:3f:d5:6b:4b:bf
Jul 12 7:07:24 PM: Awaiting adapter to come up…
Jul 12 7:07:26 PM: TAP-WIN32 device [SHHM TCP] opened: \?\root#net#0006#{adda4c48-c32e-4ef6-9602-b3252f082583}, index: 2
Jul 12 7:07:26 PM: WARNING: Failed to get IPv6 interface information for MTU. This warning can be ignored if this stack is disabled. Element not found
Jul 12 7:07:26 PM: TAP-Windows MTU=1500
Jul 12 7:07:26 PM: Waiting for DNS Setup to complete…
Jul 12 7:07:26 PM: Successful ARP Flush on interface [2] {05A8EB81-A488-4FBD-A676-268850116166}
Jul 12 7:07:27 PM: do_ifconfig, ipv4=1, ipv6=0
Jul 12 7:07:27 PM: Data Channel MTU parms [ mss_fix:1386 max_frag:0 tun_mtu:1500 tun_max_mtu:1600 headroom:136 payload:1768 tailroom:562 ET:0 ]
Jul 12 7:07:27 PM: Outgoing dynamic tls-crypt: Cipher ‘AES-256-CTR’ initialized with 256 bit key
Jul 12 7:07:27 PM: Outgoing dynamic tls-crypt: Using 256 bit message hash ‘SHA256’ for HMAC authentication
Jul 12 7:07:27 PM: Incoming dynamic tls-crypt: Cipher ‘AES-256-CTR’ initialized with 256 bit key
Jul 12 7:07:27 PM: Incoming dynamic tls-crypt: Using 256 bit message hash ‘SHA256’ for HMAC authentication
Jul 12 7:07:27 PM: Outgoing Data Channel: Cipher ‘CHACHA20-POLY1305’ initialized with 256 bit key
Jul 12 7:07:27 PM: Incoming Data Channel: Cipher ‘CHACHA20-POLY1305’ initialized with 256 bit key
Jul 12 7:07:27 PM: Data Channel: cipher ‘CHACHA20-POLY1305’, peer-id: 0
Jul 12 7:07:27 PM: Timers: ping 10, ping-restart 60
Jul 12 7:07:27 PM: Protocol options: protocol-flags cc-exit tls-ekm dyn-tls-crypt
Jul 12 7:07:31 PM: TEST ROUTES: 1/1 succeeded len=1 ret=1 a=0 u/d=up
Jul 12 7:07:31 PM: Route addition via service succeeded
Jul 12 7:07:31 PM: Initialization Sequence Completed
Jul 12 7:07:31 PM: DNS set to Split, Proxy failed to start. Please check Event Viewer for more information.
Jul 12 7:07:31 PM: State changed to Connected

Thanks

Thank you for posting that.

It looks like this is the relevant error:

DNS set to Split, Proxy failed to start. Please check Event Viewer for more information.

This indicates that Viscosity’s Split DNS engine was unable to start. The most likely cause is that third-party security or firewall software is blocking it. If you have any such software installed please try temporarily disabling or uninstalling it, and see if the problem persists. The software may have the older version of Viscosity on an allow-list, but not the latest version.

If that doesn’t help, please see if there are any error messages in Event Viewer:

Regards,
Aaron

I see nothing in the event log at that time or at the other times the user established a connection. I removed the AV and established a connection and the problem is still there. Wrote tto soon, I do see in the system log:
Log Name: System
Source: Microsoft-Windows-DistributedCOM
Date: 7/12/2026 7:07:31 PM
Event ID: 10016
Task Category: None
Level: Warning
Keywords: Classic
User: [REDACTED]
Computer: [REDACTED]
Description:
The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
to the user [REDACTED] SID (S-1-5-21-2114738819-1351435742-3001085244-1116) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.ShellExperienceHost_10.0.19041.5072_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708). This security permission can be modified using the Component Services administrative tool.
Event Xml:

10016
0
3
0
0
0x8080000000000000

602524

System
[REDACTED]

machine-default
Local
Activation
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
[REDACTED]
[REDACTED]
S-1-5-21-2114738819-1351435742-3001085244-1116
LocalHost (Using LRPC)
Microsoft.Windows.ShellExperienceHost_10.0.19041.5072_neutral_neutral_cw5n1h2txyewy
S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708

Firewall is the windows firewall. Outgoing is pretty much the default values.

The Event Viewer log entry can be safely ignored: it doesn’t appear related. Generally there should be an entry from “ViscosityService” or “ViscosityService1” under the Application logs section.

If you haven’t already done so, please try restarting your computer. Generally removing/disabling endpoint security software won’t fully take effect until after a reboot, as the drivers will still be loaded.

Attempting an uninstall and reinstall of Viscosity may be worth attempting as well, as if an AV software blocked one or more of its components from installing at update/install time, it could also explain the failure.

Regards,
Aaron