Network tools
Plan your tunnel MTU and TCP MSS
Start with the available IP MTU, then account for the headers carried inside it. This calculator works from your inputs; it does not measure a network path.
Where the bytes go
- Outer IP header
- 20 bytes
- Base GRE header
- 4 bytes
Inner IP MTU = underlay IP MTU − encapsulation overhead
Three ordinary examples
These examples use an underlay IP MTU of 1,500 bytes, IPv4 inside and outside, and no optional headers. They illustrate arithmetic, not a service configuration.
| Mode | Encapsulation overhead | Inner IP MTU | TCP MSS |
|---|---|---|---|
| IP-in-IP | 20 | 1,480 | 1,440 |
| GRE, layer 3 | 24 | 1,476 | 1,436 |
| VXLAN, inner Ethernet | 50 | 1,450 | 1,410 |
Basic GRE uses 24 bytes: 20 for outer IPv4 and 4 for GRE. If a verified path has another 24 bytes of overhead, its inner budget becomes 1,452 instead of 1,476. Neither value is universal; use the delivered settings for each tunnel.
Read the result in the right layer
The starting value is the size of an IP packet that the underlay can carry. Outer Ethernet headers, FCS, preamble and inter-frame gap are outside that IP MTU. They matter for frame sizing and wire rate, but subtracting them here again would mix two different measurement boundaries.
GRE and IP-in-IP
This GRE model carries an IP packet directly. It does not include an inner Ethernet header, ERSPAN metadata or GRE routing extensions. A checksum adds both its checksum and reserved fields; a key and a sequence field each add four more bytes. IP-in-IP adds the selected outer IP header.
VXLAN and VLANs
VXLAN carries an Ethernet frame inside UDP. Count the outer IP and UDP headers, the VXLAN header and the inner Ethernet header. The original inner FCS is not transported. Count only inner VLAN tags preserved in the encapsulated frame; a VTEP may remove or rewrite tags.
MTU, MSS and real traffic
Changing TCP MSS alone does not solve oversized UDP datagrams or every path-MTU discovery failure. Different paths, return routing, ICMP handling and offload displays can change what you observe. Validate representative TCP and UDP application exchanges, including larger payloads, on every primary and backup path.
Extra headers and exceptions
Outer IPv4 options, IPv6 extension headers and additional encapsulation are not inferred. Enter only a known extra size. Variable overhead, fragmentation, reassembly and link adaptation require their own engineering review. A short ping or an established BGP session does not certify the usable application MTU.
Questions about tunnel sizing
Is 1,476 the correct MTU for every GRE tunnel?
No. It is the result for a 1,500-byte underlay IP MTU with a basic GRE header over IPv4. Options, extra encapsulation or a smaller transport MTU change the result. Follow the values delivered for the specific connection.
Can I apply the same MTU to the primary and backup tunnels?
Only if their delivered settings and actual paths support it. A backup may use another encapsulation or transport path. Keep separate values where required and validate both paths before relying on failover.
Should I subtract TCP timestamps from the advertised MSS?
The fixed-header calculation follows RFC 6691. The sender adjusts actual TCP data length for options it uses; the MSS value is not a promise that every segment carries that many application bytes.
Does this tool test my network or change my router?
No. It accepts numeric budgets and protocol choices only. It calculates locally in the browser or from a GET form on the server and produces a text report. It does not probe an endpoint or apply a configuration.
Standards and calculation scope
Prepare the whole delivery path
Combine the byte budget with routing, port capacity and an acceptance test for legitimate application traffic.