What Is MTU (Maximum Transmission Unit)?

Related problems: Some websites or apps hang over the VPN while others work; File transfers stall over a new tunnel or private line; Performance dropped after turning on SD-WAN or encryption; Provider and our equipment disagree on packet size settings

Maximum Transmission Unit (MTU) is the largest packet, measured in bytes, that a network interface or link can carry in one piece. On most Ethernet and internet connections, the standard IP MTU is 1,500 bytes. When a packet is larger than the MTU of a link it needs to cross, it has to be split into fragments or, in many cases, dropped. MTU rarely matters until something goes wrong, typically when tunnels, encryption or a new circuit shrink the space available and some applications start to hang.

At a glance

  • MTU is the largest packet size a link or interface can carry without fragmenting it; 1,500 bytes is standard for Ethernet.
  • Tunnels such as IPsec, GRE and SD-WAN add headers, which reduces the space left for data.
  • A mismatch often shows up as partial failures: small requests work, large transfers or some websites hang.
  • Jumbo frames, often around 9,000 bytes, are used in data centers and on some private lines when every device supports them.
  • Common fixes are setting the correct MTU on interfaces and tunnels, and clamping the TCP maximum segment size.

What problem it solves

Every network link has a limit on how large a single packet can be. Devices need to agree on that limit along the whole path, or packets that are too big will not get through. MTU is the setting that defines it, and getting it right lets traffic pass without being split up or lost.

In practice, buyers meet MTU as a problem to diagnose. Adding a VPN, turning on SD-WAN or moving to a new private line can lower the effective MTU on a path. Small packets, such as the start of a connection, still pass, so the link looks up. Then larger packets fail, and users see web pages that never finish loading, file transfers that stall or applications that time out. Because the symptoms look like packet loss or an application bug, MTU problems can take a long time to find.

How it works

Interface MTU. Each interface has an MTU. For standard Ethernet the IP MTU is 1,500 bytes, with the Ethernet header added on top. Links that add their own headers, such as broadband using PPPoE, often have a lower usable MTU.

Tunnel overhead. When traffic is wrapped in a tunnel, the tunnel’s headers are added to each packet. GRE, IPsec and SD-WAN encapsulations each add their own amount, which varies with the protocol and options in use. The tunnel’s usable MTU is the underlying link’s MTU minus that overhead.

Fragmentation. In IPv4, a router can split an oversized packet into fragments, unless the packet is marked “don’t fragment,” which most modern TCP traffic is. In IPv6, routers do not fragment; only the sender can.

Path MTU discovery. When a router drops an oversized packet, it can send an ICMP message back telling the sender the smaller size. The sender then adjusts. If firewalls block those ICMP messages, the sender does not learn, and the connection hangs, a failure often called a black hole.

MSS clamping. Many routers and firewalls rewrite the TCP maximum segment size during connection setup so both sides send packets small enough for the path. It is one of the most common fixes on VPN and SD-WAN edges.

For private networks and tunnels between sites, see our Private Networking solution page.

When it matters for buyers

  • SD-WAN and VPN rollouts. Confirm how the platform sets MTU and MSS on tunnels before cutting over sites; see SD-WAN.
  • New private lines or Ethernet services. Check the MTU the provider supports end to end, especially if you plan to run your own tunnels or jumbo frames over an E-Line.
  • Cloud connections. Cloud providers publish MTU limits for their interconnects and VPN gateways, which may differ from your network.
  • Unexplained partial failures. If some sites, apps or websites fail while others work over the same link, MTU is worth checking early.

Questions to ask vendors

  • What MTU does this service support end to end, and does it support jumbo frames?
  • How much overhead does your tunnel or encryption add, and what MTU and MSS do you configure?
  • Do you clamp TCP MSS on the edge devices by default?
  • Are ICMP messages needed for path MTU discovery allowed through your network and firewalls?
  • If we stack tunnels, such as a VPN inside SD-WAN, how will packet size be handled?
  • How do you test MTU during turn-up?

How it differs from bandwidth

Bandwidth is how much data a link can carry per second, such as 100 Mbps or 1 Gbps. MTU is how large each individual packet can be. A link can have plenty of bandwidth and a small MTU, or the reverse. Raising MTU does not add bandwidth; it can slightly improve efficiency for large transfers by sending fewer headers. When a site is slow, a bandwidth shortfall usually shows up as congestion across the board, while an MTU problem usually shows up as specific connections or transfers that hang.

Frequently Asked Questions

What is the standard MTU?
For Ethernet and most internet connections, the standard IP MTU is 1,500 bytes. Some connections are smaller, for example broadband services that use PPPoE, commonly 1,492 bytes, and tunnels reduce the usable size further.
What is a jumbo frame?
A jumbo frame is an Ethernet frame larger than the standard size, often around 9,000 bytes, though the exact maximum varies by equipment and provider. Jumbo frames are common inside data centers and on some private lines, but every device on the path has to support them.
Why do tunnels cause MTU problems?
A tunnel wraps each packet in extra headers. If the original packet was already at the link's MTU, the wrapped packet is too big, so it must be fragmented or dropped. The usual fix is to lower the tunnel MTU or adjust the TCP maximum segment size.
Does a bigger MTU make the network faster?
It can improve efficiency slightly for large transfers, because there are fewer headers per byte of data. It does not add bandwidth, and a mismatch along the path can cause far worse problems than it solves.
What is MSS clamping?
MSS clamping is a router or firewall setting that lowers the maximum segment size TCP connections advertise, so the packets they send fit inside a smaller MTU, such as a tunnel's. It is a common fix for MTU problems on VPNs and SD-WAN.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.