FREE · NETWORK & IT INFRASTRUCTURE
MTU & MSS Calculator.
Calculate the usable MTU and TCP MSS through PPPoE, MPLS, WireGuard, IPsec, GRE, VXLAN and other tunnels, with clamping commands.
1500 for standard Ethernet; 9000 or more with jumbo frames.
4 bytes each when the physical MTU cannot grow.
WireGuard’s default MTU of 1420 assumes an IPv6 outer header.
- Overhead
- 80 bytes
- TCP MSS
- 1380
- Ethernet frame (with FCS)
- 1518 bytes
- TCP payload efficiency on the wire
- 89.7 % Includes preamble and inter-frame gap (20 bytes)
Commands
# Linux interface MTU
ip link set dev wg0 mtu 1420
# Clamp TCP MSS on forwarded traffic (iptables)
iptables -t mangle -A FORWARD -o wg0 -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --set-mss 1380
# nftables equivalent
nft add rule inet mangle forward oifname "wg0" tcp flags syn tcp option maxseg size set 1380
# Cisco IOS tunnel interface
ip mtu 1420
ip tcp adjust-mss 1380Overhead breakdown (bytes)
| Component | Bytes |
|---|---|
| Physical MTU | 1500 |
| Outer IP header | −40 |
| UDP header | −8 |
| WireGuard header + Poly1305 tag | −32 |
| Usable inner MTU | 1420 |
| TCP MSS (IPv4 20 + TCP 20) | 1380 |
- Path MTU discovery fails when ICMP “packet too big” or “fragmentation needed” messages are blocked; MSS clamping avoids stalled TCP connections in that case.
- Test with ping -M do -s <MTU−28> on Linux, or ping -f -l <MTU−28> on Windows.
How to use MTU & MSS Calculator
Choose the physical MTU, access encapsulation, tunnel type and outer IP version. The table shows every header; copy the interface and MSS-clamping commands.
How it works
Each layer removes its header from the available MTU. For IPsec, the inner packet plus trailer is padded to the cipher block, so the largest inner size is solved exactly. MSS is the MTU minus IP and TCP headers.
Example
WireGuard over IPv6 on a 1,500-byte link leaves an MTU of 1,420 and an IPv4 TCP MSS of 1,380.
Questions about MTU & MSS Calculator
Is MTU & MSS Calculator free, and do I need an account?
Yes. This tool is free to use in your browser without an account. Processing takes place on your device.
What are the limits and what should I check?
IPsec overhead is computed for AES-GCM or AES-CBC with HMAC-SHA-256 in tunnel mode; other algorithms differ. GRE assumes no key or sequence fields. Everything is calculated in your browser; nothing is sent or probed on the network. Review the result before using it in your work.
Is my input sent to a server?
Your input is processed in your browser and is not uploaded by this tool. Files and pasted text are cleared when the page is refreshed. Normal website requests are still required to load the page and its libraries. Read the privacy explanation.