Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    MTU bug

    Scheduled Pinned Locked Moved General pfSense Questions
    15 Posts 4 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jc1976 @jc1976
      last edited by

      @jc1976 Hey sorry for not getting back sooner.. was away for a while and just remembered..

      Anyway, no dice on the mtu settings. i released my wan ip, blanked out the MTU box.. still comes back as 1472.

      rebooted the box, same thing.. it's as if the "save" button at the bottom isn't working.. clicked on it several times but that didn't change anything.

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @jc1976
        last edited by

        @jc1976

        If you're using DHCP, then the MTU will be set automagically to whatever the ISP sets it to.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        M 1 Reply Last reply Reply Quote 0
        • M
          michmoor LAYER 8 Rebel Alliance @JKnott
          last edited by

          @jknott certainly possible but the OP stated he changed his MTU so I assume it was once at 1500

          Firewall: NetGate,Palo Alto-VM,Juniper SRX
          Routing: Juniper, Arista, Cisco
          Switching: Juniper, Arista, Cisco
          Wireless: Unifi, Aruba IAP
          JNCIP,CCNP Enterprise

          stephenw10S JKnottJ 2 Replies Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator @michmoor
            last edited by

            @michmoor said in MTU bug:

            so I assume it was once at 1500

            But maybe it wasn't. 😉

            If the MTU setting has been removed entirely from pfSense I would recommend power cycling the firewall completely. Some NICs will retain settings across a reboot.

            Steve

            JKnottJ 1 Reply Last reply Reply Quote 1
            • JKnottJ
              JKnott @michmoor
              last edited by

              @michmoor said in MTU bug:

              @jknott certainly possible but the OP stated he changed his MTU so I assume it was once at 1500

              The question becomes whether the DHCP client overrides a manual config. Normally, you don't set MTU with DHCP. Perhaps he could set the MTU before connecting and see if it retains the setting after.

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              1 Reply Last reply Reply Quote 0
              • JKnottJ
                JKnott @stephenw10
                last edited by

                @stephenw10

                Another thing he could do is run Packet Capture to see if DHCP option 26 is used and what value it is.

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Yeah it would be very unusual to see that set.

                  J 1 Reply Last reply Reply Quote 0
                  • J
                    jc1976 @stephenw10
                    last edited by

                    @stephenw10

                    My internet connection is typical cable provided by comcast/xfinity so yes, it's dhcp.

                    when i adjusted the mtu, i arrived at 1472 by plugging my laptop directly into the modem and running the commands until it stopped fragmenting, and then i used that number input the mtu size in pfsense, so i was able to adjust it.

                    i've rebooted the firewall a few times, so it's definitely locked to that number where rebooting wouldn't solve the problem.

                    seems like for me to correct the setting i'd have to manually edit a config file.

                    JKnottJ 1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      But did you fully power cycle it? Like actually remove the power rather than just reboot?

                      On many devices the NICs remain powered across a reboot and will retain their state.

                      J 1 Reply Last reply Reply Quote 0
                      • JKnottJ
                        JKnott @jc1976
                        last edited by

                        @jc1976 said in MTU bug:

                        when i adjusted the mtu, i arrived at 1472 by plugging my laptop directly into the modem and running the commands until it stopped fragmenting, and then i used that number input the mtu size in pfsense, so i was able to adjust it.

                        On the WAN interface, you have to use the MTU your ISP uses. Otherwise, some frames may be discarded. Do you know where the fragmenting is happening? It could be anywhere between you and the destination. You can determine that by looking at the source address of the ICMP messages. Fragmentation is the mechanism to get around the different MTUs and is entirely normal, though these days Path MTU Detection is often used and is mandatory with IPv6. Also, what was fragmenting? On Linux PMTUD is generally used for everything and with TCP on Windows.

                        PfSense running on Qotom mini PC
                        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                        UniFi AC-Lite access point

                        I haven't lost my mind. It's around here...somewhere...

                        J 1 Reply Last reply Reply Quote 0
                        • J
                          jc1976 @stephenw10
                          last edited by

                          @stephenw10 yes, fully powered off. changed the setting, shut the pfsense box off, turned off the modem, and went away for the weekend. Still hangs onto 1472.

                          1 Reply Last reply Reply Quote 0
                          • J
                            jc1976 @JKnott
                            last edited by

                            @jknott that i don't know.

                            I arrived at 1472 by plugging my win10 laptop directly into the modem and pinging with the flag set at whatever it was and working my way down until it stopped fragmenting. i didn't realize that the 28bits for the header were to be added onto the mtu size once the fragmentation limit was found. it's all fine, works great without any issue. just thought you'd all like to know about my experience.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.