# Looking to resolve NTP drift in Pritunls servers/clients

**URL:** <https://forum.pritunl.com/t/looking-to-resolve-ntp-drift-in-pritunls-servers-clients/3857>\
**Category:** Pritunl VPN\
**Tags:** pritunl-client, pritunl\
**Created:** [October 7, 2026, 4:59am UTC](https://forum.pritunl.com/t/looking-to-resolve-ntp-drift-in-pritunls-servers-clients/3857 "2026-10-07T04:59:02Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![macsire](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/m/8e7dd6/32.png) [@macsire](https://forum.pritunl.com/u/macsire)\
**Post date:** [October 7, 2026, 4:59am UTC](https://forum.pritunl.com/t/looking-to-resolve-ntp-drift-in-pritunls-servers-clients/3857/1 "2026-10-07T04:59:02Z")

</div>

Hello again. We are experiencing OpenVPN issues of the following quite often `AEAD Decrypt error: bad packet ID (may be a replay)`. We have correlated this to our devices where they are on cellular data and disconnect then reconnect maybe around ~13 hours to 2 days at times. (The default Pritunl sets for authentication is 12 hours.) When the device comes back online, the NTP server does not sync on the public web and is not synced to our Pritunl servers. As for solutions I have found several which I am researching to see if Pritunl can add this feature, if not I can see if it’s possible on my side:

1. Is it possible to modify the ovpn profile via Pritunl’s side? Was hoping in adding the following as a safeguard:

```auto
script-security 2
pre-up /usr/local/bin/sync-time-before-vpn.sh

```

The script I have in mind:

```bash
#!/bin/bash

chronyd -q 'server time.cloudflare.com iburst' >/dev/null 2>&1

if [$? -ne 0]; then
  HTTP_TIME=$(curl -sI --max-time 5 https://1.1.1.1 | grep -i '^date:' | cut -d' ' -f2-)
  if [-n "$HTTP_TIME"]; then
    date -s "$HTTP_TIME"
  fi
fi

exit 0

```

1. Setup chrony servers on the Pritunl servers and have the devices communicate to the servers of the correct time?

Wondering if any of these approaches would be the right choice?
