Hello again. We are experiencing OpenVPN issues of the following quite often AEAD Decrypt error: bad packet ID (may be a replay). We have correlated this to our devices where they are on cellular data and disconnect then reconnect maybe around ~13 hours to 2 days at times. (The default Pritunl sets for authentication is 12 hours.) When the device comes back online, the NTP server does not sync on the public web and is not synced to our Pritunl servers. As for solutions I have found several which I am researching to see if Pritunl can add this feature, if not I can see if it’s possible on my side:
- Is it possible to modify the ovpn profile via Pritunl’s side? Was hoping in adding the following as a safeguard:
script-security 2
pre-up /usr/local/bin/sync-time-before-vpn.sh
The script I have in mind:
#!/bin/bash
chronyd -q 'server time.cloudflare.com iburst' >/dev/null 2>&1
if [ $? -ne 0 ]; then
HTTP_TIME=$(curl -sI --max-time 5 https://1.1.1.1 | grep -i '^date:' | cut -d' ' -f2-)
if [ -n "$HTTP_TIME" ]; then
date -s "$HTTP_TIME"
fi
fi
exit 0
- Setup chrony servers on the Pritunl servers and have the devices communicate to the servers of the correct time?
Wondering if any of these approaches would be the right choice?