PasteZap
🌐 Deutsch
Kostenlos · Ohne Konto

Kostenlos · Netzwerk & IT-Infrastruktur

MTU- und MSS-Rechner.

Berechnen Sie die nutzbare MTU und den TCP-MSS durch PPPoE, MPLS, WireGuard, IPsec, GRE, VXLAN und andere Tunnel, mit Clamping-Befehlen.

Vor dem Start

Einige technische Bedienelemente sind auf Englisch. Unicode-Text wird unterstützt; Dateiformate und Ausgabesprachen hängen vom Tool ab.

Die technischen Grenzen stehen unten auf Englisch. Prüfen Sie diese vor der Verarbeitung großer Dateien und der Verwendung des Ergebnisses.

CALCULATED IN YOUR BROWSER · NOTHING IS UPLOADED

1500 for standard Ethernet; 9000 or more with jumbo frames.

4 bytes each when the physical MTU cannot grow.

WireGuard’s default MTU of 1420 assumes an IPv6 outer header.

Inner MTU1420MSS 1380
Overhead
80 bytes
TCP MSS
1380
Ethernet frame (with FCS)
1518 bytes
TCP payload efficiency on the wire
89.7 %
Includes preamble and inter-frame gap (20 bytes)

Commands

# Linux interface MTU
ip link set dev wg0 mtu 1420

# Clamp TCP MSS on forwarded traffic (iptables)
iptables -t mangle -A FORWARD -o wg0 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --set-mss 1380

# nftables equivalent
nft add rule inet mangle forward oifname "wg0" tcp flags syn tcp option maxseg size set 1380

# Cisco IOS tunnel interface
ip mtu 1420
ip tcp adjust-mss 1380

Overhead breakdown (bytes)

ComponentBytes
Physical MTU1500
Outer IP header−40
UDP header−8
WireGuard header + Poly1305 tag−32
Usable inner MTU1420
TCP MSS (IPv4 20 + TCP 20)1380
  • Path MTU discovery fails when ICMP “packet too big” or “fragmentation needed” messages are blocked; MSS clamping avoids stalled TCP connections in that case.
  • Test with ping -M do -s <MTU−28> on Linux, or ping -f -l <MTU−28> on Windows.

So verwenden Sie das Tool: MTU- und MSS-Rechner

Geben Sie Daten ein oder wählen Sie eine Datei. Passen Sie die Einstellungen an, erstellen Sie das Ergebnis und prüfen Sie es vor dem Kopieren oder Herunterladen.

Grenzen und unterstützte Formate

Ihre Eingaben werden auf Ihrem Gerät verarbeitet.

Technische Hinweise auf Englisch

IPsec overhead is computed for AES-GCM or AES-CBC with HMAC-SHA-256 in tunnel mode; other algorithms differ. GRE assumes no key or sequence fields. Everything is calculated in your browser; nothing is sent or probed on the network.

Each layer removes its header from the available MTU. For IPsec, the inner packet plus trailer is padded to the cipher block, so the largest inner size is solved exactly. MSS is the MTU minus IP and TCP headers.

WireGuard over IPv6 on a 1,500-byte link leaves an MTU of 1,420 and an IPv4 TCP MSS of 1,380.