Skip to content
PEERYXNETWORK

Network tools

Plan your tunnel MTU and TCP MSS

Start with the available IP MTU, then account for the headers carried inside it. This calculator works from your inputs; it does not measure a network path.

576–9,216 bytes. Use the smallest known IP MTU on the transport path, not the Ethernet frame size or the advertised port speed.
Header options

Include only headers actually present. GRE options apply to GRE; inner VLAN tags apply to VXLAN. Fields for other modes are ignored.

0, 1 or 2 inner tags, at 4 bytes each. Do not count an outer VLAN tag twice: the starting value is already an IP MTU.
0–512 bytes for another encapsulation or known extra headers. This is an explicit allowance, not an automatic model of IPsec, PPPoE or every vendor tunnel.
Reset

Where the bytes go

Outer IP header
20 bytes
Base GRE header
4 bytes

Inner IP MTU = underlay IP MTU − encapsulation overhead

Three ordinary examples

These examples use an underlay IP MTU of 1,500 bytes, IPv4 inside and outside, and no optional headers. They illustrate arithmetic, not a service configuration.

ModeEncapsulation overheadInner IP MTUTCP MSS
IP-in-IP201,4801,440
GRE, layer 3241,4761,436
VXLAN, inner Ethernet501,4501,410

Basic GRE uses 24 bytes: 20 for outer IPv4 and 4 for GRE. If a verified path has another 24 bytes of overhead, its inner budget becomes 1,452 instead of 1,476. Neither value is universal; use the delivered settings for each tunnel.

Read the result in the right layer

The starting value is the size of an IP packet that the underlay can carry. Outer Ethernet headers, FCS, preamble and inter-frame gap are outside that IP MTU. They matter for frame sizing and wire rate, but subtracting them here again would mix two different measurement boundaries.

GRE and IP-in-IP

This GRE model carries an IP packet directly. It does not include an inner Ethernet header, ERSPAN metadata or GRE routing extensions. A checksum adds both its checksum and reserved fields; a key and a sequence field each add four more bytes. IP-in-IP adds the selected outer IP header.

VXLAN and VLANs

VXLAN carries an Ethernet frame inside UDP. Count the outer IP and UDP headers, the VXLAN header and the inner Ethernet header. The original inner FCS is not transported. Count only inner VLAN tags preserved in the encapsulated frame; a VTEP may remove or rewrite tags.

MTU, MSS and real traffic

Changing TCP MSS alone does not solve oversized UDP datagrams or every path-MTU discovery failure. Different paths, return routing, ICMP handling and offload displays can change what you observe. Validate representative TCP and UDP application exchanges, including larger payloads, on every primary and backup path.

Extra headers and exceptions

Outer IPv4 options, IPv6 extension headers and additional encapsulation are not inferred. Enter only a known extra size. Variable overhead, fragmentation, reassembly and link adaptation require their own engineering review. A short ping or an established BGP session does not certify the usable application MTU.

Questions about tunnel sizing

Is 1,476 the correct MTU for every GRE tunnel?

No. It is the result for a 1,500-byte underlay IP MTU with a basic GRE header over IPv4. Options, extra encapsulation or a smaller transport MTU change the result. Follow the values delivered for the specific connection.

Can I apply the same MTU to the primary and backup tunnels?

Only if their delivered settings and actual paths support it. A backup may use another encapsulation or transport path. Keep separate values where required and validate both paths before relying on failover.

Should I subtract TCP timestamps from the advertised MSS?

The fixed-header calculation follows RFC 6691. The sender adjusts actual TCP data length for options it uses; the MSS value is not a promise that every segment carries that many application bytes.

Does this tool test my network or change my router?

No. It accepts numeric budgets and protocol choices only. It calculates locally in the browser or from a GET form on the server and produces a text report. It does not probe an endpoint or apply a configuration.

Standards and calculation scope

Prepare the whole delivery path

Combine the byte budget with routing, port capacity and an acceptance test for legitimate application traffic.

Protected IP transit ↗Defense Fabric deployment guide ↗Gbps and packet-rate calculator ↗Choose an architecture ↗