---
title: "What is MTU and how a wrong value breaks your connection | StreetHosting"
description: "Learn what the 1500 byte MTU is, what changes with PPPoE and VPN, how fragmentation and PMTUD work, and how to find the right value on Linux and Windows."
url: "https://streethosting.com.br/en/guides/infrastructure/what-is-mtu"
type: "page"
language: "en-US"
---

Infrastructure · 9 min · Intermediate

Published on Sep 28, 2026 · Updated on Sep 28, 2026

# MTU in practice: fragmentation, PMTUD and the black hole that hangs connections

MTU sets the largest packet that crosses a link without being split. When it is wrong somewhere along the path, the connection opens and ping answers, yet websites, VPNs and downloads still hang.

By [Equipe StreetHosting](https://streethosting.com.br/en/autores#equipe-streethosting) · StreetHosting infrastructure and support team

[Network, DNS and domains](https://streethosting.com.br/en/guides/topics/networking) [Latency and ping](https://streethosting.com.br/en/guides/topics/latency)

Summarize with:

[](https://chat.openai.com/?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-mtu.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "ChatGPT") [](https://claude.ai/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-mtu.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Claude") [](https://www.google.com/search?udm=50&aep=11&q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-mtu.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Google AI Mode") [](https://x.com/i/grok?text=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-mtu.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Grok") [](https://www.perplexity.ai/search/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-mtu.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Perplexity")

Share:

[](https://x.com/intent/tweet?text=What%20is%20MTU%20and%20how%20a%20wrong%20value%20breaks%20your%20connection&url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-mtu "Share on X") [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-mtu "Share on Facebook") [](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-mtu "Share on LinkedIn") [](https://wa.me/?text=What%20is%20MTU%20and%20how%20a%20wrong%20value%20breaks%20your%20connection%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-mtu "Share on WhatsApp")

For agents: Copy as Markdown [.md](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu.md)

In this guide 7 sections

* [What MTU is](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#o-que-e-mtu)
* [PPPoE, VPN and tunnels](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#overhead)
* [Fragmentation](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#fragmentacao)
* [PMTUD and the ICMP black hole](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#pmtud)
* [How to find the path MTU](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#testar)
* [How to fix it](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#corrigir)
* [MTU under your control](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#onde-rodar)

Quick answer

**MTU** (Maximum Transmission Unit) is the size of the largest IP packet a link carries without splitting it into pieces. On Ethernet the default is 1500 bytes; on PPPoE it drops to 1492 and inside a VPN it gets smaller still. When some point along the path has a smaller MTU and the ICMP messages that report it are blocked, large packets vanish: ping works, the connection opens, but HTTPS, downloads and VPNs hang. The test is `ping -M do -s 1472` on Linux or `ping -f -l 1472` on Windows.

## What MTU is[](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#o-que-e-mtu)

Every network technology has a limit on the size of the frame it can carry. MTU is that limit measured from IP's point of view: how many bytes of packet, counting the IP header, fit in a single frame. On Ethernet that is 1500 bytes. The Ethernet header and the error check sit outside that count.

Those 1500 bytes hold the IP header (20 bytes on IPv4, 40 on IPv6), the transport header (20 bytes for TCP, 8 for UDP) and the data. On TCP, the space left for data is called MSS (Maximum Segment Size). With an MTU of 1500 on IPv4, the MSS is 1460 bytes. Both ends announce their own MSS at the start of the connection, and that will matter later on.

The MTU that matters is not your network card's but the smallest MTU along the whole path, called the Path MTU. A single hop with a lower limit, such as a tunnel or a PPPoE connection, sets the maximum size for the entire connection.

## PPPoE, VPN and tunnels[](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#overhead)

MTU shrinks every time someone wraps the packet in one more header. PPPoE, used by many fiber and DSL carriers in Brazil, takes 8 bytes of each frame, so the connection's MTU drops to 1492. VPNs and tunnels do the same on a larger scale: each original packet becomes the payload of a new packet, with IP, UDP and the tunnel header on the outside.

| Scenario                     | Overhead                             | Typical MTU | TCP MSS on IPv4 |
| ---------------------------- | ------------------------------------ | ----------- | --------------- |
| Standard Ethernet            | None                                 | 1500        | 1460            |
| PPPoE                        | 8 bytes                              | 1492        | 1452            |
| GRE                          | 24 bytes                             | 1476        | 1436            |
| VXLAN                        | 50 bytes                             | 1450        | 1410            |
| WireGuard over IPv4          | 60 bytes                             | 1440        | 1400            |
| WireGuard with automatic MTU | Reserves 80 bytes, with IPv6 in mind | 1420        | 1380            |
| IPsec                        | Varies with the cipher               | Around 1400 | Around 1360     |
| Minimum required by IPv6     | Not applicable                       | 1280        | Not applicable  |

Stacked tunnels add up their overhead. A WireGuard tunnel leaving a home with PPPoE has, in practice, 1492 minus 80, or 1412 bytes available. If the tunnel is still configured at 1420, full packets exceed the limit and the trouble begins. This is one of the most common scenarios when someone builds the tunnel described in the guide on [CGNAT and using a VPS as a public endpoint](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat).

Jumbo frames, with an MTU of 9000, exist on internal datacenter and storage networks. On the public internet the ceiling is still 1500, and setting 9000 on a server's public interface only creates problems.

## Fragmentation[](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#fragmentacao)

When a packet larger than the MTU reaches a smaller link, there are two ways out: split the packet into fragments, or drop it and tell the sender. On IPv4 the router can fragment, but only if the packet does not have the DF (Don't Fragment) bit set. On IPv6 no router fragments; only the sender can.

Fragmenting looks like a fix, but it is expensive:

* **Multiplied loss:** if one fragment goes missing, the whole packet is discarded at the destination, and the retransmission sends every fragment again.
* **Extra work:** the destination has to hold the pieces and reassemble the packet, which uses memory and CPU.
* **Firewalls that drop fragments:** many filters cannot evaluate a fragment that lacks the transport header and simply throw it away.

That is why modern TCP sets the DF bit on every packet and prefers to discover the right size rather than depend on fragmentation. Protocols over UDP, such as games and QUIC, keep their datagrams small for the same reason. The behavioral difference between the two protocols is covered in [TCP vs UDP on servers](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp).

## PMTUD and the ICMP black hole[](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#pmtud)

PMTUD (Path MTU Discovery) is the mechanism that finds the smallest MTU on the path. The sender transmits packets with DF set. If a router in the middle cannot pass the packet, it drops it and returns an ICMP message: fragmentation needed on IPv4, packet too big on IPv6, always carrying the MTU that fits. The sender shrinks the size and carries on.

The whole mechanism depends on that ICMP message making it back. When a firewall along the path drops ICMP, the sender never finds out. It keeps sending large packets, they keep disappearing, and the connection hangs. This is called a PMTUD black hole, and the symptoms are confusing because everything small works:

* **Ping and the handshake go through:** they are small packets, so the first diagnosis says the network is fine.
* **HTTPS hangs at the start:** the certificate sent by the server fills full-size packets and never arrives.
* **SSH freezes:** the login gets in, but a command that returns a lot of text leaves the terminal stuck.
* **A download starts and stops:** apt, git clone and rsync transfers sit at zero bytes per second.
* **The VPN connects but nothing browses:** the tunnel comes up, some sites open and others do not.
* **The game logs in but never loads:** the login passes, but loading the world, which sends a lot of data at once, can stay stuck.

The most common cause is a firewall rule that blocks all ICMP to hide the server. Blocking the echo request only removes ping, which is acceptable. Blocking destination unreachable on IPv4 or packet too big on IPv6 breaks PMTUD. Ubuntu's default UFW already allows the required types in the `/etc/ufw/before.rules` file; the problem appears when someone edits that file or uses a ready-made firewall script. See the guide on [the UFW firewall on a VPS](https://streethosting.com.br/en/guides/vps/ufw-firewall-ubuntu-vps).

## How to find the path MTU[](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#testar)

The test is to send pings with DF set and keep lowering the size until they get through. The size you give ping is only the payload: on IPv4, add 8 bytes of ICMP header and 20 of IP header. That is why a 1472 byte payload makes a 1500 byte packet.

`# Linux, IPv4: 1472 + 28 = 1500 ping -M do -s 1472 -c 3 IP_DA_VPS # Linux, IPv6: 1452 + 48 = 1500 ping -6 -M do -s 1452 -c 3 ENDERECO_IPV6 # Windows (Command Prompt or PowerShell) ping -f -l 1472 IP_DA_VPS`

Read the result like this:

1. **Normal replies:** the path handles 1500 bytes and MTU is not your problem.
2. **An error message:** on Linux, `message too long, mtu=1492` or `Frag needed and DF set (mtu = 1492)`; on Windows, `Packet needs to be fragmented but DF set`. PMTUD is working and has already told you the limit. Lower the size and confirm.
3. **Silence, no reply and no error:** a sign of a black hole, or of a destination that drops large pings. Lower the size in steps of 10 until it starts answering again and note the largest value that gets through.

On Linux, `tracepath -n IP_DA_VPS` runs the search for you and shows at which hop the MTU drops, ending with a line like `Resume: pmtu 1492 hops 11 back 11`. It works like a traceroute that also measures MTU, and reading the hops follows the same logic as the guide on [using traceroute to find routing problems](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute).

## How to fix it[](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#corrigir)

The fix depends on where the narrow hop is. In order of preference:

* **Allow the required ICMP:** if the black hole is in your own firewall, letting the destination unreachable and packet too big messages back in fixes it without touching anything else.
* **Adjust the tunnel MTU:** on WireGuard, set `MTU = 1380` in the `[Interface]` section on both ends when either one sits behind PPPoE or another tunnel. The base configuration is in [a WireGuard VPN on your VPS](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps).
* **MSS clamping on the gateway:** if you route traffic for other machines, such as a VPN gateway, rewrite the MSS announced at the start of each TCP connection so it fits the path. Most home PPPoE routers already do this on their own.
* **MTU probing on the server itself:** Linux can detect a black hole on TCP connections and shrink the size on its own when the `net.ipv4.tcp_mtu_probing` option is set to 1.
* **Lower the interface MTU:** a last resort, when the limit is on a hop you do not control and nothing above fixed it.

The matching commands, to run as root on the VPS or the gateway:

`# check the current MTU of the interfaces ip link show # MSS clamping for forwarded traffic (VPN gateway) iptables -t mangle -A FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu # TCP MTU probing, persistent echo "net.ipv4.tcp_mtu_probing=1" > /etc/sysctl.d/99-mtu.conf sysctl --system # interface MTU, for testing only (back to normal on reboot) ip link set dev eth0 mtu 1450`

On Windows, each interface's MTU shows up with `netsh interface ipv4 show subinterfaces`. After fixing it, measure throughput again with [iperf3 to test your VPS speed](https://streethosting.com.br/en/guides/vps/test-vps-network-speed): black holes and fragmentation cut the transfer rate long before they cut the connection.

Changing the MTU on a VPS's public interface can cut off your own SSH access if the value ends up wrong. Test first with `ip link set`, which disappears on reboot, and keep the VPS console at hand before making the change permanent in netplan. With `sudo netplan try` the configuration rolls back on its own if you do not confirm within two minutes.

## MTU under your control[](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#onde-rodar)

Fixing an MTU problem takes access to what sits along the path: the interface, the firewall, ICMP and the MSS rules. On shared hosting or in an unprivileged container, none of that is in your hands. On [StreetHosting VPS](https://streethosting.com.br/en/vps) the virtualization is KVM, with its own kernel and root access, so you adjust the MTU, load the WireGuard module and write whatever iptables or nftables rules you need.

* **VPN or tunnel gateway:** the R$ 26.00 Xeon VPS, with 2 vCPU, 2 GB of RAM and 20 GB of NVMe, is more than enough for WireGuard with MSS clamping for a home or a small office.
* **Game server or application:** the [Ryzen 9 9950X VPS](https://streethosting.com.br/en/vps/ryzen) starts at R$ 40.00 with 1 vCPU and 2 GB of DDR5 and goes up to R$ 846.00 with 14 vCPU and 64 GB, always with NVMe and a 1 Gbps uplink.

All of them are in São Paulo, with Anti-DDoS included and activation within 60 seconds after payment by Pix, boleto or card.

In this guide

* [What MTU is](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#o-que-e-mtu)
* [PPPoE, VPN and tunnels](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#overhead)
* [Fragmentation](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#fragmentacao)
* [PMTUD and the ICMP black hole](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#pmtud)
* [How to find the path MTU](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#testar)
* [How to fix it](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#corrigir)
* [MTU under your control](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu#onde-rodar)

## Frequently asked questions

What is the default MTU of the internet?

The default on Ethernet networks is 1500 bytes, and it is the value most of the internet uses. PPPoE connections, common on residential fiber and DSL, sit at 1492. Tunnels such as WireGuard use less, 1420 by default, because they reserve room for their own header.

How do I find the right MTU for my connection?

Send pings with the do not fragment bit set, at decreasing sizes, until they get through. On Linux use ping -M do -s 1472 and on Windows ping -f -l 1472. The largest size that gets through, plus 28 bytes of IPv4 headers, is the path MTU.

Does a wrong MTU cause lag in games?

Rarely. Game packets are usually small and fit in any MTU. A wrong MTU shows up in other symptoms: a login that never completes, a download that stalls, a site that loads halfway and a VPN that connects but opens nothing.

What is MSS clamping?

It is a rule on the router or VPN gateway that rewrites the maximum segment size announced at the start of each TCP connection. That way both ends never send segments larger than the path can carry. It only works for TCP, and it fixes most MTU problems on tunnels.

Does blocking ping on the server get in the way of MTU?

Blocking the echo request, which is the regular ping, does not. What breaks MTU discovery is blocking the ICMP destination unreachable messages on IPv4 and packet too big messages on IPv6. Dropping all ICMP indiscriminately is what creates the MTU black hole.

Next step

See VPS plans

Root VPS in Brazil with NVMe and Anti-DDoS.

[See VPS plans](https://streethosting.com.br/en/vps)

[See Ryzen VPS Ryzen 9 9950X VPS in São Paulo with root access, NVMe and gamer Anti-DDoS.](https://streethosting.com.br/en/vps/ryzen)

## Related guides

[Infrastructure Intermediate TCP vs UDP: which protocol to use on each server TCP guarantees everything arrives, and in the right order. UDP delivers what it can without waiting for anyone. Understanding that trade explains why games and voice use UDP, why APIs use TCP and why opening lots of ports in the firewall does not work. 9 min Read guide](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp) [VPS Advanced How to set up a WireGuard VPN on your VPS for private access Instead of exposing panels and databases to the internet, put everything behind a VPN. WireGuard is lightweight, fast and simple to configure, and it gives you secure private access to your VPS services. 3 min Read guide](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps) [Infrastructure Intermediate How to use MTR to diagnose network problems MTR combines traceroute and ping and shows, hop by hop, where latency climbs and where packets get lost. The trick is knowing which loss is real and which is just a router rationing its replies. 8 min Read guide](https://streethosting.com.br/en/guides/infrastructure/how-to-use-mtr)

[← Back to the Guide Center](https://streethosting.com.br/en/guides)
