Network

MTU and MSS Calculator

Calculate the correct MTU and TCP MSS for a path with tunnels, VLAN tags or PPPoE, and understand why a connection completes its handshake and then hangs on the first large transfer.

Last reviewed by the Radiatus Cloud team

Calculation appears here.

Need this monitored 24/7?

Radiatus delivers managed cloud & network operations.

Discuss managed ops

The failure looks like anything except an MTU problem

A path with a reduced MTU produces one of the most confusing failure modes in networking. Small packets pass, so the TCP handshake completes, DNS works and a ping succeeds. The connection then hangs the moment a full sized packet is sent, which in practice means the page loads and then stalls, or the SSH session connects and freezes on the first long output. Because everything small works, the investigation usually starts everywhere except the MTU.

Path MTU discovery relies on ICMP that is often blocked

The mechanism that should handle this sends a packet with the do not fragment bit set, and a router that cannot forward it returns an ICMP fragmentation needed message telling the sender the correct size. When a firewall blocks ICMP type 3, that message never arrives, the sender keeps retransmitting the same oversized packet, and the connection stalls indefinitely. This is the single most common cause of an MTU black hole, and blocking all ICMP is how it gets created.

MSS clamping fixes it at the gateway

Rather than relying on discovery, a gateway can rewrite the maximum segment size in passing TCP SYN packets so both endpoints agree on a size that fits. This works regardless of whether ICMP is filtered and regardless of what the endpoints believe their MTU to be. It applies only to TCP, so UDP based protocols such as QUIC and VPN encapsulation still need the MTU set correctly on the interface.

Related tools

  • Port Scanner — Check which common ports respond on a host and understand what each exposed service means. Scan only systems you are authorised to test.
  • DNS Misconfiguration — Analyze DNS records (TXT, SPF) for security gaps.
  • TLS Compat Tester — Check client-server compatibility for TLS versions.
  • Firewall Rule Risk — Evaluate firewall rules for over-permissive exposure.

Frequently Asked Questions

What is the difference between MTU and MSS?

MTU is the largest frame payload a link carries, including the IP and TCP headers. MSS is the TCP payload only, so it is the MTU less 20 bytes of IPv4 header and 20 of TCP header. A 1500 MTU gives an MSS of 1460 on IPv4 and 1440 on IPv6.

Why does everything work except large transfers?

Small packets fit within the reduced MTU so the handshake, DNS and ping all succeed. The first full sized packet cannot be forwarded, and if the ICMP message that would report this is blocked, the sender retransmits it forever and the connection hangs.

What is an MTU black hole?

A path where oversized packets are dropped and the ICMP fragmentation needed message is filtered, so the sender never learns the correct size. Blocking all ICMP at a firewall is how these are usually created; type 3 code 4 must be permitted.

Should I lower MTU or clamp MSS?

Clamp MSS at the gateway for TCP, since it works regardless of ICMP filtering and requires no endpoint change. Lower the interface MTU as well where UDP based traffic such as QUIC or nested tunnels also traverses the path, because clamping only affects TCP.

Why is a WireGuard MTU 1420?

1500 less 20 bytes of outer IPv4 header, 8 of UDP, 4 of WireGuard type and counter, 4 of receiver index, 8 of nonce and 16 of Poly1305 authentication tag. Over IPv6 the outer header is 40 bytes rather than 20, so the usual figure is 1400.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Choose your encapsulation layers to get the effective MTU and the MSS to clamp to.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.