無料 · ネットワーク・IT インフラ
MTU・MSS 計算機.
PPPoE、MPLS、WireGuard、IPsec、GRE、VXLAN などを通した有効 MTU と TCP MSS を計算し、MSS クランプのコマンドも示します。
1500 for standard Ethernet; 9000 or more with jumbo frames.
4 bytes each when the physical MTU cannot grow.
WireGuard’s default MTU of 1420 assumes an IPv6 outer header.
- Overhead
- 80 bytes
- TCP MSS
- 1380
- Ethernet frame (with FCS)
- 1518 bytes
- TCP payload efficiency on the wire
- 89.7 % Includes preamble and inter-frame gap (20 bytes)
Commands
# Linux interface MTU
ip link set dev wg0 mtu 1420
# Clamp TCP MSS on forwarded traffic (iptables)
iptables -t mangle -A FORWARD -o wg0 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --set-mss 1380
# nftables equivalent
nft add rule inet mangle forward oifname "wg0" tcp flags syn tcp option maxseg size set 1380
# Cisco IOS tunnel interface
ip mtu 1420
ip tcp adjust-mss 1380Overhead breakdown (bytes)
| Component | Bytes |
|---|---|
| Physical MTU | 1500 |
| Outer IP header | −40 |
| UDP header | −8 |
| WireGuard header + Poly1305 tag | −32 |
| Usable inner MTU | 1420 |
| TCP MSS (IPv4 20 + TCP 20) | 1380 |
- Path MTU discovery fails when ICMP “packet too big” or “fragmentation needed” messages are blocked; MSS clamping avoids stalled TCP connections in that case.
- Test with ping -M do -s <MTU−28> on Linux, or ping -f -l <MTU−28> on Windows.
使い方: MTU・MSS 計算機
データを入力するかファイルを選び、設定を調整して結果を生成します。コピーやダウンロードの前に結果を確認してください。
制限と対応形式
入力内容はお使いの端末で処理されます。
英語の技術説明
IPsec overhead is computed for AES-GCM or AES-CBC with HMAC-SHA-256 in tunnel mode; other algorithms differ. GRE assumes no key or sequence fields. Everything is calculated in your browser; nothing is sent or probed on the network.
Each layer removes its header from the available MTU. For IPsec, the inner packet plus trailer is padded to the cipher block, so the largest inner size is solved exactly. MSS is the MTU minus IP and TCP headers.
WireGuard over IPv6 on a 1,500-byte link leaves an MTU of 1,420 and an IPv4 TCP MSS of 1,380.