Maximum Transmission Unit (MTU) is the largest packet, measured in bytes, that a network interface or link can carry in one piece. On most Ethernet and internet connections, the standard IP MTU is 1,500 bytes. When a packet is larger than the MTU of a link it needs to cross, it has to be split into fragments or, in many cases, dropped. MTU rarely matters until something goes wrong, typically when tunnels, encryption or a new circuit shrink the space available and some applications start to hang.
At a glance
- MTU is the largest packet size a link or interface can carry without fragmenting it; 1,500 bytes is standard for Ethernet.
- Tunnels such as IPsec, GRE and SD-WAN add headers, which reduces the space left for data.
- A mismatch often shows up as partial failures: small requests work, large transfers or some websites hang.
- Jumbo frames, often around 9,000 bytes, are used in data centers and on some private lines when every device supports them.
- Common fixes are setting the correct MTU on interfaces and tunnels, and clamping the TCP maximum segment size.
What problem it solves
Every network link has a limit on how large a single packet can be. Devices need to agree on that limit along the whole path, or packets that are too big will not get through. MTU is the setting that defines it, and getting it right lets traffic pass without being split up or lost.
In practice, buyers meet MTU as a problem to diagnose. Adding a VPN, turning on SD-WAN or moving to a new private line can lower the effective MTU on a path. Small packets, such as the start of a connection, still pass, so the link looks up. Then larger packets fail, and users see web pages that never finish loading, file transfers that stall or applications that time out. Because the symptoms look like packet loss or an application bug, MTU problems can take a long time to find.
How it works
Interface MTU. Each interface has an MTU. For standard Ethernet the IP MTU is 1,500 bytes, with the Ethernet header added on top. Links that add their own headers, such as broadband using PPPoE, often have a lower usable MTU.
Tunnel overhead. When traffic is wrapped in a tunnel, the tunnel’s headers are added to each packet. GRE, IPsec and SD-WAN encapsulations each add their own amount, which varies with the protocol and options in use. The tunnel’s usable MTU is the underlying link’s MTU minus that overhead.
Fragmentation. In IPv4, a router can split an oversized packet into fragments, unless the packet is marked “don’t fragment,” which most modern TCP traffic is. In IPv6, routers do not fragment; only the sender can.
Path MTU discovery. When a router drops an oversized packet, it can send an ICMP message back telling the sender the smaller size. The sender then adjusts. If firewalls block those ICMP messages, the sender does not learn, and the connection hangs, a failure often called a black hole.
MSS clamping. Many routers and firewalls rewrite the TCP maximum segment size during connection setup so both sides send packets small enough for the path. It is one of the most common fixes on VPN and SD-WAN edges.
For private networks and tunnels between sites, see our Private Networking solution page.
When it matters for buyers
- SD-WAN and VPN rollouts. Confirm how the platform sets MTU and MSS on tunnels before cutting over sites; see SD-WAN.
- New private lines or Ethernet services. Check the MTU the provider supports end to end, especially if you plan to run your own tunnels or jumbo frames over an E-Line.
- Cloud connections. Cloud providers publish MTU limits for their interconnects and VPN gateways, which may differ from your network.
- Unexplained partial failures. If some sites, apps or websites fail while others work over the same link, MTU is worth checking early.
Questions to ask vendors
- What MTU does this service support end to end, and does it support jumbo frames?
- How much overhead does your tunnel or encryption add, and what MTU and MSS do you configure?
- Do you clamp TCP MSS on the edge devices by default?
- Are ICMP messages needed for path MTU discovery allowed through your network and firewalls?
- If we stack tunnels, such as a VPN inside SD-WAN, how will packet size be handled?
- How do you test MTU during turn-up?
How it differs from bandwidth
Bandwidth is how much data a link can carry per second, such as 100 Mbps or 1 Gbps. MTU is how large each individual packet can be. A link can have plenty of bandwidth and a small MTU, or the reverse. Raising MTU does not add bandwidth; it can slightly improve efficiency for large transfers by sending fewer headers. When a site is slow, a bandwidth shortfall usually shows up as congestion across the board, while an MTU problem usually shows up as specific connections or transfers that hang.
