The safe approach is to treat a path-by-path MTU baseline that finds the largest reliable packet, preserves management access, and validates the original transfer as a sequence of observable gates, not a single command.
On a home network containing NAS, VLAN, and VPN routes, the practical risk is small requests work while larger NAS or VPN transfers stall on one routed or tagged path. Record the current identity and recovery point, start with the least invasive discriminator, interpret pass and fail results before changing another variable, and stop when storage becomes unstable or the only recoverable copy would be exposed. The workflow below ends only after the original workload succeeds or the evidence reaches an escalation boundary.
Define each path and preserve a recovery route
List the exact client-to-NAS routes you need to test: ordinary LAN, each routed VLAN, and every VPN profile. Record physical NICs, bonds, bridges, VLAN subinterfaces, virtual switches, tunnel interfaces, router hops, and the current MTU shown at each layer; the route actually selected matters more than the diagram you intended.
Keep one verified management path at MTU 1500 or arrange local console access before changing the NAS interface. The related ZimaSpace diagnosis for MTU mismatch or packet loss separates a repeatable packet-size boundary from random loss, making it the right neighboring check when a transfer stalls but small traffic survives.
Capture a known-good small ping, DNS lookup, NAS login, SMB or NFS mount, and disposable file write on every path. Stop if the only administration route is uncertain, because an MTU experiment should never turn a performance question into a locked-out server.
Find the largest reliable payload in both directions
Start with normal small packets, then increase the payload while preventing IPv4 fragmentation or using the platform-appropriate IPv6 test. Account for IP and ICMP headers rather than treating payload size as interface MTU, and run the test from client to NAS and NAS to client.
Path MTU discovery depends on feedback when a packet cannot traverse the next link. The APNIC discussion of path MTU black-hole behavior explains why filtered control messages can create a black-hole condition in which smaller exchanges succeed while larger traffic wedges.
Record the highest repeatable payload for each route and the first failing size. If failures move between runs, investigate loss, Wi-Fi quality, or congestion first; an MTU ceiling should appear at a consistent threshold rather than as random packet loss.
Locate the smallest hop instead of lowering everything
Compare the measured ceiling with every interface on the selected route. VPN encapsulation reduces usable payload, a VLAN interface may inherit or override its parent, and a bridge or virtual switch may be the smaller hop even when both physical endpoints advertise jumbo frames.
Change one component at a time, beginning with the infrastructure that must permit the frame and ending with one test endpoint. Do not raise MTU across the entire LAN to fix one storage path, and do not use MSS clamping as a permanent answer until the failing boundary and affected TCP direction are confirmed.
Repeat the packet sweep after each change. A pass means both directions reach the planned size without loss and all smaller paths remain usable; a fail means restore the last value and keep the measured ceiling as the safe route limit.
Validate with the original NAS and VPN workload
Run the same large-file transfer, backup stream, or remote mount that exposed the problem, using the same client, protocol, encryption, and route. Compare throughput, stalls, retransmissions, and application logs with the saved baseline rather than judging from ping alone.
Test a second time after reconnecting the VPN and after a client or NAS restart, because interface order and tunnel MTU can change during recreation. Confirm ordinary MTU-1500 clients still browse, read, write, and reconnect to the NAS.
Keep the change only when the original workload completes twice and every management path remains reachable. Roll back when the reliable ceiling differs by route, and escalate with route, interface, packet-size, and capture evidence if control messages disappear beyond equipment you manage.
Support & Tips
More to Read

Live TV Recording Storage Guide for Capacity, Retention, and Cleanup
Measure real recordings, reserve headroom, combine age and capacity limits, and prove the oldest eligible program is removed before storage fills.

Home Media Metadata Recovery Workflow After a Database Restore
Protect the restored state, verify media identity and paths, then repair missing artwork or matches in a pilot library before broad metadata changes.

Jellyfin Client Compatibility Checklist for Audio, Video, and Subtitles
Test representative files one variable at a time and record Direct Play, remux, audio conversion, video transcode, or failure for every client.

