What is MTU, and why does the wrong setting break some websites?
Maximum transmission unit is the largest packet size a link will carry — and a mismatch produces one of the most confusing faults in networking: most things work, but some websites hang after loading part of the page.
The standard sizes. Ethernet's MTU is 1500 bytes. Some connections carry less: PPPoE, used on many broadband services, adds 8 bytes of overhead and reduces the usable MTU to 1492; VPN tunnels subtract more; some mobile and satellite links are lower again.
What happens to an oversized packet. Traditionally, a router could fragment it into pieces and the destination would reassemble them. In IPv4 this is still possible unless the Don't Fragment (DF) flag is set — and in practice it usually is, because fragmentation is inefficient and problematic. IPv6 does not permit routers to fragment at all.
So instead, the router discards the packet and sends back an ICMP "Fragmentation Needed" message stating the maximum size it can carry. The sender then reduces its packet size for that destination. This mechanism is Path MTU Discovery.
Why it fails. The mechanism depends entirely on that ICMP message getting back. Many firewalls block all ICMP as a blunt security measure. When that happens:
The oversized packets vanish silently.
The sender never learns why, and keeps retransmitting at the same size.
Small packets get through fine. The handshake succeeds, the connection establishes, and small responses arrive.
Large transfers hang. The page starts loading and then stops.
This is the PMTUD black hole, and its signature is unmistakable: some sites work perfectly, others connect and then stall, and the problem follows the network rather than the device.
Where it shows up most: VPN connections, PPPoE broadband, tunnelled connections, and some hosting configurations.
How to diagnose it. Send progressively larger pings with fragmentation disabled and find where they stop being answered. The largest that succeeds, plus header overhead, is your usable path MTU.
Fixes: lower the MTU on the router or VPN interface; enable MSS clamping, which rewrites TCP's advertised segment size so it fits — the standard remedy on consumer routers; and stop blocking all ICMP.