Tunnelblick
The Tunnelblick Project · A free, open-source macOS interface for OpenVPN connections using your own VPN server access, configuration and authentication credentials.
About
Tunnelblick is a free macOS graphical interface for OpenVPN. Use its menu-bar controls and VPN Details window to connect or disconnect configurations, inspect connection logs and configure connection behavior. It is useful for people accessing an employer's private network, an independently operated OpenVPN server or a compatible VPN provider.
A client interface, not a VPN subscription
Tunnelblick supplies the OpenVPN software and supporting components. It does not supply a VPN service, provider account or remote server. Obtain a trusted OpenVPN configuration and the required certificates, keys or credentials from your administrator or provider. Advanced OpenVPN server configurations are also supported by the interface, but installing the app alone does not provision a hosted server. Tunnelblick is not a general WireGuard or other-protocol client.
Mac installation
Tunnelblick 9.0.1 build 6491 is a notarized Universal application for Intel and Apple Silicon Macs running macOS 13 or newer. The DMG download is 29,196,962 bytes; installed storage differs. For security reasons, the application must be installed in /Applications. Installation requires administrator authorization so its privileged components and protected files can be installed securely. The app includes OpenVPN; no additional Homebrew package dependencies or conflicts are declared. Built-in update checks are available.
Profiles, networking and privileges
Import the configuration supplied for your server and review its origin before use. OpenVPN configurations can reference certificates, authentication helpers and scripts. Tunnelblick protects configuration ownership because VPN operation and configuration scripts can require elevated privileges; untrusted profiles or scripts can affect your Mac. Protect private keys and any credentials stored for automatic connections.
A reachable compatible server and correct authentication are required. Routing, DNS, IPv4 and IPv6 behavior depend on the profile and server settings. A connected indicator does not prove that every application or all traffic uses the VPN. Other VPN clients, conflicting routes, firewall restrictions and legacy network extensions can interfere with operation. Older TAP configurations and system extensions can have additional macOS limitations; use the provider's supported configuration rather than assuming every historical profile works on current Macs.
Costs, accounts and privacy
Tunnelblick is licensed under GNU GPL version 2 and is free to use, with optional donations. It has no mandatory Tunnelblick account or subscription. A company or external VPN provider can require its own account and charge for server access. VPN encryption covers the tunnel to the server; the provider, destination services and routing choices still affect privacy. Tunnelblick does not promise anonymity. Its setup offers update checks and checks for public IP address changes; review these options and the project's privacy guidance when configuring the app.
New What’s new in 9.0.1 Oct 7 · OpenNavo editorial
- ChangesInclude OpenVPN 2.7.7, replacing 2.7.6.
Caveats
For security reasons, tunnelblick must be installed to /Applications, and will request to be moved at launch.