Skip to content

Poll: most cursed MTU you've encountered in the wild?

Networking by haroldgsm 21 replies 2K views
10 #1

20 years in this business and I thought I'd seen everything. Back when we ran everything on T1s, 576 was normal. Kids these days complain about 1280 on IPv6 tunnels.

But last week I found a Contabo edge router set to 1400 exactly. Not 1492. Not 1480. 1400. "For safety," they said. Someone read a blog post about PPPoE overhead and rounded down. Twice.

I'm collecting horror stories. What's the most pathologically wrong MTU you've seen deployed intentionally? Mark my words, we're going to find something worse than my 1400 story.

IPv4, IRC, and irssi — fight me
#2

1400 "for safety" is just chef's kiss. Did they also wear a helmet to check email?

grabs popcorn, checks /r/drama
#3

Locked threads don't get votes. Keep it technical.

No logs, no proof. I have logs.
3 #4

Simple is better. I saw
576 on a "modern" DSL line in 2019 because the CPE defaulted to it and nobody checked

#5

The reasoning is always "a blog post recommended headroom."

From a privacy perspective, path MTU discovery failures leak significant metadata about network topology. A fixed low MTU is sometimes deployed intentionally to force fragmentation, which certain middleboxes use for traffic analysis. I am not suggesting this was the case with Contabo, but the practice has implications beyond mere performance degradation.

Neuland. Aber schnell.
#6

1400 for pppoe overhead doesn't even add up

builds at 3AM, sleeps at noon
#7

I had a client insist on 1300 "for vpn headroom"

6 #8
liam_funky said:
I had a client insist on 1300 "for vpn headroom"

Did you also explain that their IPSec site-to-site was already handling its own fragmentation? I've seen that stack twice: OpenVPN inside IPSec, both with "headroom." The packets looked like Russian nesting dolls.

#9

The real cursed MTU is whatever my ISP in Tallinn uses on their CGNAT. Can't path MTU discover because they drop ICMP. Can't fragment because the app doesn't set DF. Everything just... hangs.

builds at 3AM, sleeps at noon
#10
tallinnying said:
They drop ICMP

This is the actual epidemic. 1400 is dumb but honest. Silently blackholing ICMP Fragmentation Required is malicious incompetence. Half my tickets in the last five years trace back to this.

IPv4, IRC, and irssi — fight me

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft