How to Match MTU Settings Across a NAS, Switch, Router, and VPN

Eva Wong is the Technical Writer and resident tinkerer at ZimaSpace. A lifelong geek with a passion for homelabs and open-source software, she specializes in translating complex technical concepts into accessible, hands-on guides. Eva believes that self-hosting should be fun, not intimidating. Through her tutorials, she empowers the community to demystify hardware setups, from building their first NAS to mastering Docker containers.

Use the largest MTU that the complete path can carry reliably, not the largest number shown by one device. For most mixed NAS, router, and VPN paths, a consistent 1500-byte baseline is safer than enabling jumbo frames selectively.

The common failure is deceptively specific: small pings and web pages work, while a large SMB copy, backup, or VPN upload stalls. That happens when one hop accepts a frame size that a later hop cannot forward and the feedback needed for path-MTU discovery is lost. Record the current values first, test the path in both directions, and change only one layer at a time.

Map the path before changing MTU

Draw the actual route from client to NAS, including Wi-Fi access points, managed-switch trunks, router interfaces, virtual bridges, and the VPN tunnel. MTU is an interface property, so a value on the NAS does not prove that every intervening segment accepts the same payload.

Start with the physical LAN and the tunnel as separate paths. A VPN adds headers, reducing the payload that fits inside the outer packet; the practical path MTU can therefore shrink even when every Ethernet interface remains at 1500.

Save screenshots or command output for every relevant interface. If you cannot identify a hop or its MTU, keep the baseline at 1500 and do not enable jumbo frames yet; an unknown managed switch, virtual switch, or tunnel is a stop condition.

Measure the physical and VPN paths

From a wired client, send do-not-fragment probes toward the NAS and increase the payload gradually. On IPv4, remember that the ICMP and IP headers consume part of the packet; interpret the tool's packet-size semantics instead of assuming its argument is the MTU.

Repeat from the NAS toward the client and then across the VPN. A pass in both directions at the expected size means the tested path can carry that packet; a failure only through the tunnel points to tunnel overhead or a blocked ICMP response, not automatically to the NAS.

Confirm with a multi-gigabyte transfer and watch for retransmissions, pauses, or a connection that succeeds only after lowering the probe size. If even the 1500-byte LAN baseline fails, restore defaults and inspect tagging, encapsulation, or defective links before attempting optimization.

Align values from the narrowest hop outward

Keep switch access and trunk ports consistent with the attached endpoints. If you choose jumbo frames for an isolated storage VLAN, every participating NIC, bridge, and switch port on that VLAN must support the chosen frame size; the router does not need jumbo frames unless the traffic crosses it.

For the VPN, set the tunnel MTU from the measured tunnel path rather than copying the LAN value. Avoid changing TCP MSS until you have confirmed that TCP alone is affected; MSS clamping can mitigate TCP symptoms but does not repair oversized UDP or a generally broken path.

Apply one reversible change, retest, and retain the lower working value if results disagree. If you are also tuning file-sharing behavior, the ZimaSpace guide to SMB and NFS choices helps keep protocol decisions separate from MTU troubleshooting.

-15% OFF
Single board computer zimaboard2

Validate under the original workload

Repeat the transfer that originally stalled, using the same client, route, VPN state, and file size. A valid fix removes the stall without increasing packet loss or breaking smaller clients on another VLAN.

Run the test long enough to cross several gigabytes and compare throughput stability, not just the peak number. If direct LAN transfers pass but VPN transfers still pause, revert the VPN change and lower only the tunnel MTU in small steps.

Stop when both directions pass the probe and the original workload completes consistently. Abandon jumbo frames when any required device cannot be configured or when the gain is not measurable; consistency is more valuable than a nominal 9000-byte setting.

FAQ

Must every device on the home network use MTU 9000? No. Only devices and ports on the jumbo-frame path must agree, and routed or tunneled paths may still require a smaller value.

Does a successful ping prove the MTU is correct? Only if the probe uses the intended size, prevents fragmentation where applicable, passes both directions, and is followed by the real transfer test.

Support & Tips

More to Read

Get More Builds Like This

Stay in the Loop

Get updates from Zima - new products, exclusive deals, and real builds from the community.

Stay in the Loop preferences

We respect your inbox. Unsubscribe anytime.