Path maximum transmission unit is the largest packet a route can carry without fragmentation or a size-related drop. An overlay, VPN, or tunnel can reduce usable payload below the host interface MTU. Small health requests may work while larger TLS records or uploads stall. Packet-size failure must be separated from application timeout, DNS, and server capacity faults; an ICMP result from one segment does not prove the entire client-to-service path is healthy.
Path MTU: find the packet size that breaks an otherwise healthy route
Operational decision
A receipt API accepts a short status request but hangs when a client uploads a 31-kilobyte attachment through a private tunnel. Capture the client path, tunnel endpoint, gateway, and backend address for the same attempt. Compare a small and a large request with identical authentication and routing. The read-only trace below can reveal a lower path MTU on a Linux host, but some middleboxes do not return useful control messages; pair it with packet capture or endpoint counters where available. Check whether the tunnel clamps TCP maximum segment size and whether ICMP needed for path discovery is blocked. Test IPv4 and IPv6 separately if both are served. Reduce packet size only as a controlled diagnostic, then fix the transport or tunnel policy and verify sustained uploads from the real client network. Record request size, retransmissions, and timeout phase so a successful ping does not close the incident.
tracepath -n receipt-gateway.internal
ip -s link show dev eth0Cost and verification
A smaller tunnel MTU may add packets, CPU, and per-packet overhead for every large transfer. A larger value can look efficient in a benchmark while silently failing on one route. Extra packet capture has privacy and storage costs, so filter to synthetic test traffic and retain only what the investigation needs. Measure upload completion rate by size, retransmissions, and effective path MTU before and after the fix. The trace command is Linux-specific and its output depends on intermediate devices.
Common Mistakes
- Do not treat a short ping as proof that large application payloads work.
- Do not lower every host MTU before identifying the failing segment.
- Do not assume an IPv4 result also validates the IPv6 path.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- DNS, TLS, and reverse-proxy failure boundaries
- Egress policy and DNS: restrict destinations without breaking name resolution
- NAT port pressure: find the shared outbound ceiling
- Synthetic transactions: measure the route a user actually takes
