Troubleshooting · Networking and Wi-Fi
Troubleshoot VPN MTU and PMTUD Black Holes
If small pings succeed while HTTPS stalls, investigate path MTU. IPsec and other tunnels reduce usable inner packet size through encapsulation overhead. When required ICMP feedback is…
Technical review:
Architecture and operating model
If small pings succeed while HTTPS stalls, investigate path MTU. IPsec and other tunnels reduce usable inner packet size through encapsulation overhead. When required ICMP feedback is blocked, the sender may repeatedly send oversized packets and stall.
Do not equate all ICMP filtering with ping security. IPv4 fragmentation-needed and IPv6 Packet Too Big support path discovery. MSS clamping affects TCP only; UDP and QUIC require separate tunnel-MTU and application packet-size tests.
- 1Large packet
- 2Tunnel overhead
- 3ICMP MTU feedback
- 4Sender adaptation
Design parameters
- Payload size
- Add 20 bytes IPv4 and 8 bytes ICMP to ping payload size; IP options and additional encapsulation change the calculation.
- Encapsulation overhead
- It varies with cipher mode and NAT-T; do not impose one constant on every tunnel.
- Feedback
- Validate ICMP sources and allow required error types in policy.
Worked example
A Linux DF ping with 1472 payload bytes creates a 1500-byte IPv4 packet. If 1372 succeeds and 1472 fails, search between them. Validate the boundary with TCP transfers and the relevant UDP application; one ping is not a universal MTU measurement.
Example commands: replace lab values and confirm permissions and software versions before use.
ping -4 -M do -s 1372 -c 3 192.0.2.20
tracepath 192.0.2.20
tcpdump -ni eth0 "icmp or icmp6"
Troubleshooting
| Observation | Likely cause / distinction | Verification |
|---|---|---|
| Small requests work, uploads stall | Oversized packet loss or ICMP filtering. | Capture retransmissions and ICMP feedback together. |
| MSS fixed but QUIC still fails | MSS does not affect UDP. | Measure UDP datagram size and tunnel MTU. |
Acceptance checks
- Measure size before/after encapsulation.
- Verify required ICMP types.
- Probe the boundary with DF.
- Test TCP and UDP separately.
- Scope MSS changes narrowly.
- Measure reverse-direction MTU too.
Related concepts
MTU along the path
MTU concerns packet size on a link; tunnelling and encapsulation headers can reduce space available for useful payload. Small requests working while large transfers stall may suggest an MTU issue, but this is not proof. TCP MSS and interface MTU are distinct. Compare both endpoints and tunnel interfaces. Identify the affected segment with controlled tests instead of changing every device, and remember that blocked ICMP error messages can complicate path-MTU discovery.
Bandwidth and useful throughput
Link capacity differs from useful application throughput. Protocol headers, encryption, retransmissions, small files and storage waits reduce net transfer speed. Keep bits and bytes distinct: 1 Gbit/s corresponds to a theoretical 125 MB/s, not an application performance guarantee. Estimate transfer time as data size divided by measured useful throughput. Observe the network, source reads and destination writes together to locate the bottleneck. Consider temporary slowdowns and competing workloads as well as average speed.
Latency distribution
Latency is the time between starting an operation and receiving its result. An average can hide a small number of very slow operations; medians and p95/p99 percentiles answer different questions. Network RTT, storage waits, processor queues and application processing contribute to end-to-end time. State whether measurements come from the client or server. Check whether increases coincide with traffic growth, maintenance or capacity limits. Record normal and peak-hour baselines before selecting an alert threshold.
Telemetry and time correlation
Telemetry combines logs, metrics and events that explain system behaviour. A log describes an event, a metric shows behaviour over time, and a distributed trace follows a request across components. Clock differences can make one event appear to occur at several times. Use synchronized clocks, reliable source identifiers and consistent time-zone handling. Alarm design should consider duration and user impact alongside thresholds. Monitor gaps in collection separately: absence of logs must not be interpreted as absence of incidents.
Layer 2 and Layer 3 boundaries
A VLAN creates a separate broadcast domain; routing and access policies govern communication between VLANs. Review trunk allowed lists, access-port assignment and gateway placement together. A network diagram should show where packets are routed and filtered, not merely which cables connect devices. Sharing a switch does not require sharing privileges. When access fails, confirm VLAN and addressing first, then gateway, route and policy matching.
TLS and certificate validation
TLS protects confidentiality and integrity in transit; certificate validation helps verify the peer’s identity. Evaluate names, chains, validity periods and trusted roots together. Encryption does not prove correct application authorization. If a reverse proxy or inspection device is used, show where TLS terminates. Disabling validation is not a permanent troubleshooting solution: investigate hostname mismatch, missing intermediate certificates and incorrect device clocks separately.
Primary documentation
Prepared by the Doz Teknoloji technical team using the primary references below. Calculations and lab scenarios state their assumptions; validate the applicable product version before rollout.