Ch. 20 · Networking

Networking: MTU and Fragmentation

Why the MTU limits packet size, how path MTU discovery avoids fragmentation, and why tunnels cause black-hole connections.

~2 min readadvancedupdated Oct 5, 2026

The maximum transmission unit (MTU) is the largest packet a link will carry, typically 1500 bytes on Ethernet. When a packet is larger than a link’s MTU, it must be fragmented or rejected, and tunnels such as VPNs reduce the effective MTU, which is a frequent cause of connections that hang on large transfers.

Before you start

You should understand IP packets and basic routing. This article covers MTU, fragmentation and path MTU discovery.

Step-by-step walkthrough

Every link has an MTU, and the smallest MTU along a path limits the packet size end to end. Sending a packet larger than a link’s MTU forces the sender or a router to fragment it, which adds overhead and can be blocked.

Step 2: Path MTU discovery avoids fragmentation

With the DF (don’t fragment) flag set, a router that cannot forward an oversized packet returns an ICMP “fragmentation needed” message, and the sender reduces its packet size. This is path MTU discovery, and it depends on those ICMP messages reaching the sender.

Step 3: Tunnels shrink the usable MTU

Encapsulation such as a VPN or VXLAN adds headers, so the payload MTU inside the tunnel is smaller than the underlying link. If PMTUD is blocked, for example by a firewall dropping ICMP, the sender never learns to reduce its size and large packets vanish silently, a “black hole”.

Worked scenario

The probe finds the largest size that passes without fragmentation.

ping -M do -s 1472 example.com   # 1472 + 28 bytes headers = 1500 MTU
# smaller succeeds, larger is dropped if PMTUD is broken
Terminal

Walk through the example

-M do sets the don’t-fragment flag and -s 1472 sets the payload size, so a 1500-byte packet is sent. If it passes, the path supports that MTU; if larger payloads are dropped, PMTUD is not working and large transfers will stall. This probe is how you confirm an MTU black hole.

Common mistake

Assuming all packets succeed because small ones do, while large transfers hang because of an MTU mismatch inside a tunnel. Another is firewalling all ICMP, which breaks PMTUD and reintroduces the black hole.

Verify the behavior

Probe increasing payload sizes with the don’t-fragment flag and find the largest that passes. Compare with a tunneled path and note the smaller MTU. Confirm the connection stalls on a large transfer and recovers when MTU discovery works.

Interview exercise

Why can a connection work for small requests but hang on large ones?

Answer and reasoning

Small requests fit in a single packet under the path MTU, so they pass. A large response requires packets at or above the reduced MTU of a tunnel, and if PMTUD is blocked by dropped ICMP, the sender never learns to shrink them, so those packets are silently discarded and the transfer stalls. The fix is to allow the ICMP messages or clamp the MSS.

Continue learning

Compare transport behavior in UDP trade-offs and reliability in Reliable byte stream. Read the RFC 1191 path MTU discovery and try the Networking interview questions.

More in Networking

read ✓Networking · mid

Networking: DNS Caching and TTL

Understand positive and negative caching, why changes are not instant, and how TTL trades propagation speed against query load.

~2 min readread →
read ✓Networking · easy

Networking: DNS Record Types

Read and choose DNS records: A and AAAA for addresses, CNAME for aliases, and MX and TXT for mail and verification.

~2 min readread →
read ✓Networking · mid

Networking: HTTP Redirects

Choose between 301, 302, 307 and 308, know which preserve the request method, and avoid caching and loop mistakes.

~2 min readread →
esc