
MTU is a size limit. The largest packet a link will accept without chopping it. Ethernet often lives near 1500 bytes. A VPN adds a wrapper: extra headers around the inner packet. The cafe path that loaded mail just fine can start dropping the fat ones. Some sites hang. A call chops. Steam does something weird. Small pages still work, which is how people decide the VPN is haunted instead of oversized.
A VPN is still a hop. Wikipedia's VPN page is the noun. RFC 8446 is TLS 1.3 on the website. TLS did not pick your packet size. Cloudflare's what is MTU explainer is the follow link for the height-limit metaphor. Read it as their network story. It is not a Klox slider. We do not ship a consumer MTU picker in this article. If a branded client has a field, confirm with sales. Do not invent one so a farm screenshot looks copied.
This is not Why WireGuard Is Faster Than OpenVPN. That piece is why the protocol is light: handshake, crypto, codebase. This is not How to Read a VPN Speed Test Without Lying to Yourself. Ookla is a lab. The site you actually use is the job. A stall that is MTU can sit next to a fat speed-test number. This is not OpenVPN TCP vs UDP: Which to Choose. Transport is a cousin. Size limits are this URL. This is not HTTP/3 and QUIC vs a VPN in Plain English. QUIC is encrypted UDP to the site. MTU is whether the wrapped packet still fits the path.
KloxVPN is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, 7-day money-back on first purchase. Features lists DNS through the tunnel, IPv6 leak protection, WebRTC leak blocking. The documented lever when a path is rude is protocol: WireGuard first, OpenVPN from download advanced settings when UDP dies or the path stalls in a way a protocol change actually fixes. There is no city count. There is no custom-DNS picker. There is no SLA that we clamp MTU to a number I will print. Cookies on this site live at /cookie. A cookie page is not a packet size.
I have a bias. Switch protocol once if the cafe path plus the tunnel hangs in a way that looks like size, not speed. Stop collecting MTU calculators. Do not treat a ranked Mbps list as Path MTU Discovery. Do not claim we tuned every underpass on the internet.
Related reading: White-Label VPN and IPV6 Toggle Copy and Rdtscp: Not a Mitigation Toggle. Linux reachable_time: Not a VPN Setting and Linux record_size_limit: Not a VPN Setting. What is a VPN? and VPN kill switch.
Looking for a reliable VPN?
KloxVPN — from $2.83/month. Apps for every device.
Packet size on a cafe plus a tunnel
Picture a truck and a tunnel with a height limit. The truck was fine on the surface street. Wrap it in another truck and it clips the underpass. MTU is that limit for packets. The cafe AP, the hotel concentrator, a cheap LTE hop, a home ISP that already wrapped you in their own tunnel: any of those can be shorter than the 1500 you assumed. Add WireGuard or OpenVPN headers and the inner payload has to shrink or the packet has to fragment. Fragmentation is messy. A lot of paths refuse it. Then the fat packet dies quietly.
You do not need a lab to use the idea. You need to stop treating 'VPN is slow' as one disease. Throughput can be fine. Latency can be fine. A particular site still hangs because that site wanted a large segment and the path dropped it. Speed-test servers often use sizes and paths that survive. Your bank's upload, a VoIP burst, a game update, a WebRTC turn: different sizes. Different leftover.
Farms will still rank 'best VPN MTU setting 2026' as if a consumer slider were a personality. Some self-hosted WireGuard users do set an MTU. That is a lab they run. Klox consumer is an app with two protocols. I will not invent a third SKU named MTU so we look like a router firmware page. The lever that exists is WireGuard versus OpenVPN on the download apps' advanced settings. Use it as that.
HTTPS sits on top either way. RFC 8446 does not pick segment size for you. The padlock on a hanging site means the cafe is not reading the body. It does not mean the body arrived. Two locks, still. This post is the underpass, not the padlock essay.
- 1Skim the seating / order diagram.
- 2Do the numbered steps once on your real network.
- 3Use the FAQ if a sentence was too long.
- 4Follow one related article — not ten tabs.
How to read this page
| What you see | Likely old | Speed-test tab | First lever to try |
|---|---|---|---|
| Small pages load, large uploads hang | Size limit plus tunnel headers | Can still look fat | WireGuard to OpenVPN, or the reverse |
| VoIP chop, video tile freeze | Bursts plus a rude path MTU | Mbps may look fine | Protocol switch, then a real call |
| Steam or a game updater stalls | Fat TCP, ICMP for PMTUD blocked | Unrelated lab | Protocol, then the actual download |
| Everything is slow, including ping | Radio, CPU, distant node, not MTU | Also slow | This is the speed-test essay, not this URL |
| UDP blocked, WireGuard never handshakes | Transport, not packet height | Never ran | OpenVPN, often TCP, from advanced settings |
| Cookie on klox.app | Unrelated | Unrelated | See /cookie; neither is a packet size |
The cafe path had a size limit. The tunnel added wrapping. Some packets no longer fit. That is not a city-count fix.
— KloxVPN consumer notes
Cloudflare Learning: What is a VPN?
Wikipedia: Virtual private network
A fat lab is not a fitting path
Ookla can fill a pipe with packets that survive. A site that wanted a larger segment can still die. Measure the job you actually have, not the screenshot.
What this post is not
Not why WireGuard is light. Not how to read a speed test. Not TCP versus UDP as a transport course. Not QUIC. This URL is packet height on a tunneled cafe path.
What a stall looks like
The useful picture is split. Small HTTPS pages load. A form submit hangs. A call starts and then the other person sounds underwater on your side only. Steam sits at a percent. A video tile in a meeting freezes while chat still types. Those are size-shaped. Everything crawling, including ping and DNS, is usually radio, CPU, or a node a continent away. That leftover belongs to the speed-test essay and the WireGuard-speed essay. Do not bring an MTU story to a congested cafe AP.
You notice MTU when the failure is picky. One host. One direction. One app that sends larger writes. Browsers retry. Some stacks Path-MTU-Discover and recover. Some black-hole: the packet with Don't Fragment set hits a short link, ICMP 'too big' never comes back, the sender never shrinks, the session waits until it gives up. Cloudflare's fragmentation notes are blunt about ICMP getting filtered. Cafe gear filters ICMP for sport. VPN paths add another place for that ICMP to die.
I will not perform ping -M do -s theater. If you already live in packet captures, you know the test. If you do not, you do not need to start now. Trust the split: picky hang versus whole-path slowness. Protocol switch is the consumer lever. A slider I invent in JSON is not.
Five devices share an account, not a packet-size budget I made up. Each connected client is a seat. Two laptops on the same rude AP will fight the radio long before they fight Klox headers. Test one machine. Leave the rest alone for two minutes. Then interpret.
NordVPN's slow-VPN post is a competitor specimen of the mash: speed, servers, protocol, and sometimes a hidden network tweak in one ranking costume. Use it as a specimen. Do not import a winner. There is no winner. There is a height limit, a wrap, and a protocol you can change.
Picky hang versus whole-path slowness
If ping and small pages are fine, think size. If nothing moves, think radio, CPU, distance, or a handshake that never finished. Different essays.
VoIP is not Ookla
A call cares about delay, jitter, and whether bursts fit. A megabit screenshot answers a file. Bring the real call after you switch protocol, not a second lab.
Fragmentation without a lab
IPv4 can fragment. In practice a lot of senders set Don't Fragment and expect Path MTU Discovery. IPv6 forbids routers to fragment. If the packet is too big, it dies unless the sender already knew to shrink. A VPN is a tunnel: inner packet plus outer headers. The outer packet has to fit the cafe path. If the inner assumed 1500 and the outer ate 60 to 80 bytes, you are over. Some stacks clamp. Some do not on that OS, that protocol, that minute.
Home fiber often looks like a clean 1500. The stall shows up on the trip: hotel concentrator, airplane thin pipe, a phone hotspot that already wrapped you, LTE that lives closer to 1428 or 1280 depending on the carrier's own tunnel. You did not change Klox. The underpass changed. That is why a setting you never touched 'broke Steam' on Tuesday and was fine on the couch. Protocol switch is still the first consumer move. Re-testing at home tells you whether the leftover was the cafe.
I will not print 'we clamp MTU to N.' That would be an SLA we did not write. Client and server and path all participate. A blog number becomes a ticket when the path is 1280 on LTE and 1500 at home. Operators who run their own WireGuard pick a number for their lab. You are using an app. The app's documented knob is protocol.
ICMP is the control message that says 'too big, try smaller.' Middleboxes drop ICMP because someone told them it was an attack surface. Then PMTUD goes blind. Classic black hole. Symptoms look like a broken site, not like a missing ICMP. You cannot fix the hotel's ICMP policy from Klox Settings. You can try the other protocol, which encapsulates differently and sometimes takes a path that already learned a smaller size.
Do not disable IPv6 as a personality because an MTU blog mentioned v6. IPv6 leak protection is a different leftover: a home v6 that walked around a v4 tunnel. Size limits can happen on v4 alone. Mash them and you will file two tickets as one.
Headers eat budget
The inner TLS record did not get smaller because you bought a hop. The outer packet did get larger. Something has to give: shrink, fragment, or drop. Drop is what a hang feels like.
ICMP silence is a black hole
If 'too big' never arrives, the sender keeps offering oversized packets. The path keeps dropping them. A protocol change is a different encapsulation, not a new cafe.
WireGuard versus OpenVPN as the lever
Klox ships four protocols. WireGuard is UDP, light, the default I want. OpenVPN can run UDP or TCP, including the spare-tire mode when a rude AP blocks WireGuard's UDP. That is the lever on download advanced settings. Confirm the rows in the live app. I will not invent a third row named MTU.
Why a protocol change can fix a size-shaped stall: different header tax, different inner MSS behavior, different code path for clamping, sometimes TCP which changes how loss looks. Why it can fail to fix one: the underpass is still short, ICMP is still dead, the app you care about still writes large. Then you are in 'this network is hostile' territory, not 'I need a slider.' Try a phone on cellular. Try home. Seven days on first purchase if the product cannot live on the network you actually have.
This is still not the TCP-versus-UDP course. That URL owns reliability layers and firewalls. Here the only point is: the documented consumer move is protocol, not a number you typed from a forum. Forum numbers are someone else's lab. 1280, 1420, 1380: those are folklore until you measured. We are not measuring for you in this post. We are refusing a fake SKU.
Smart Connect, if the row exists, is untrusted Wi-Fi. It starts a hop. It does not probe Path MTU as a product feature I will advertise. If handshake hangs, you may not have a route yet. Splash page first. Garden essay owns that. Size leftover comes after you have a tunnel that actually passed packets.
Yearly from $2.83 a month does not buy a personal MTU engineer. It buys five seats and two protocols. Use the second protocol before you open a calculator.
If OpenVPN still hangs on the fat app, try the phone on cellular with WireGuard. Different radio, different path, often a different size limit. If cellular is clean and the hotel is not, you learned the chair. If both hang, you may have a device CPU leftover or an app that hates tunnels for its own reasons. Gaming lag and VoIP each have their own URLs. This page will not become those. DNS through the tunnel still has to work or you will misread a name failure as a size failure. One leftover at a time.
Advanced settings, not a slider SKU
WireGuard, then OpenVPN. That is the pair we document. A field in another brand's app is their client. I will not clone it in JSON. Confirm the live Settings screen. If a row is missing, you still have Connect and a protocol picker somewhere in advanced settings. Use those.
TCP is a spare tire, not a size guarantee
OpenVPN on TCP can pass a firewall that hates UDP. It can also feel worse under loss. It is not a promise that every large upload now fits. Try it. Then judge the real app.
This is not a speed-test essay
A nearby Ookla run is a lab. Distance, Wi-Fi, protocol tax, phone CPU, and the site you actually use: that honesty lives on How to Read a VPN Speed Test Without Lying to Yourself. I will point at it. I will not paste the table so this URL can rank for Mbps. MTU stalls can coexist with a pretty lab. That is the whole reason this page exists as a sibling, not a subsection.
Why WireGuard Is Faster Than OpenVPN is why the default protocol is quick: handshake, crypto, small codebase. A light protocol still adds headers. Light is not 'fits every underpass.' Do not uninstall WireGuard because a cafe dropped large segments. Switch to OpenVPN once. Switch back at home. Do not live in OpenVPN TCP because one hotel was rude.
We do not publish Mbps guarantees. We do not publish city counts on this blog so a 'fastest VPN' farm can scrape them. Nearby is usually enough when the job is 'hide this hop from the shop,' not 'pretend I live in a catalog.' Catalogs are a different article. Size limits are not a catalog problem.
If the speed-test tab and the real site disagree, believe the real site. If both are fine except one fat upload, you are in this essay. If both are bad, start with radio and protocol as speed, not as MTU folklore.
Mbps can lie next to a hang
A fill-rate lab does not prove every segment size survived. Use the app you came for as the test. Then stop collecting screenshots.
Light protocol, still a wrap
WireGuard being faster than OpenVPN on a clean path does not delete headers. Speed and fit are different leftover physics.
QUIC is a different leftover
HTTP/3 rides QUIC over UDP and encrypts the web session. A VPN is a tunnel to a node you picked. The cafe still sees UDP to an IP. That mash is the HTTP/3 and QUIC vs a VPN in Plain English essay. MTU can still bite QUIC: UDP datagrams have a size, and a tunnel wrap still eats budget. Do not merge the tickets. Encrypted transport is not a hop wrap. A hop wrap is not an HTTP/3 toggle. We do not ship an HTTP/3 toggle.
WireGuard is also UDP. Different destination. Cafe graphs 'UDP to the VPN' when you are connected, not 'UDP to the site,' unless something leaked around the tunnel. Size limits apply to that outer UDP too. If a hotel hates UDP entirely, you will never get to the MTU conversation. OpenVPN TCP is the spare tire. That is transport. Then, if TCP is up and large posts still hang, you are back on this page.
I will not invent a consumer UI that disables QUIC inside the tunnel. The site and the browser still negotiate that. I will not invent a city so QUIC 'works better.' Protocol is the lever. Padlock stays on. RFC 8446 still encrypted the inner session after the hop.
DNS through the tunnel still matters. A hanging site can be a resolver leftover, not MTU. If names never resolve, fix DNS before you blame packet height. The DNS-on-a-VPN article owns that hop. Do not stack a public resolver as a vitamin. We are not selling a custom-DNS picker here.
UDP to the site versus UDP to a node
QUIC to a CDN is one socket. WireGuard to Klox is another. Size limits can hit either. The QUIC essay owns the mash. This essay owns the underpass.
No route, no MTU story
If WireGuard never handshakes, you have a portal or a UDP block. Finish the garden. Try OpenVPN. Then see whether the hang is picky.
No consumer MTU picker
I will say it again because farms screenshot sliders. Klox consumer, in this article, has no MTU picker. No advertised clamp-to-N. No 'set 1420 for Steam' support macro I am going to publish as product. White-label or a self-hosted lab can have different glass. Confirm with sales if you are that buyer. You are probably not. You have two protocols and five devices.
What a size-hide still cannot do: make the AP honest. Scan the attachment. Unlock a catalog I did not promise. Replace unique passwords. SOC 2 because a buyer likes logos. The What a VPN Cannot Do list owns the cape. An MTU stall is a path problem. Encryption of a path that drops large packets is still a path that drops large packets.
Cookies on klox.app live at /cookie. They are not an MTU setting. A tracker cookie plus a hanging upload is two chores. Fix the hang with protocol. Leave cookies to the cookie page.
If a competitor's Linux guide tells you to type an MTU into wg0, that is their lab. Mullvad and Proton and a pile of forum posts live there. Specimen, not a SKU. Importing their number into a consumer ticket is how L1 spends a day proving the app does not have the field.
Forum numbers are someone else's lab
1280 on Android, 1380 on a router, 1420 on Windows: those are experiments. They are not Klox Settings. Protocol is.
No clamp-to-N SLA
I will not print a byte count we promise on every cafe AP. Paths differ. The honest consumer sentence is: try the other protocol, then judge the real app.
After connect, one honest check
Connect. Load a small site. Load the fat thing you actually care about: the call, the upload, the updater. If the small site works and the fat thing hangs, switch WireGuard to OpenVPN (or back) in advanced settings. Try the fat thing once more. Then stop. Daily protocol hopping is how people forget to live.
If you want proof the hop moved, that is the Leak Test After You Connect a VPN article. IP, DNS, WebRTC, IPv6. A leak test will not print MTU. Do not demand it. If the IP is the VPN and the fat app still hangs, you have a path-size leftover, not a leak leftover.
Do this once on a network you control, once on the cafe that hurt you. Different underpasses. A clean home test is not a clean hotel test. Splash first if there is a garden. Then tunnel. Then the fat app.
Yearly from $2.83 a month is not a reason to skip the padlock. It is a reason you can afford the hop without a farm's lifetime coupon. Seven days on first purchase if the product is not the hop you wanted. Refunds live on /refund. Store purchases follow the store.
If you only needed the English, stop here. If you needed why WireGuard is light, that URL exists. If you needed how to read a lab, that honesty post exists. If you needed TCP versus UDP, that guide exists. If you needed QUIC, that sibling exists. If you needed a slider, you wanted a forum.
Small site, then the real job
A homepage is not Steam. A speed-test tab is not a meeting. Use the thing that hung as the signal. Then switch protocol once.
One afternoon, then stop
Download the apps. Connect on the rude network after the splash. Try the other protocol. Notice whether the fat app moved. Then use the habit. Do not collect MTU folklore as a personality.
Key Takeaways
MTU is a packet size limit. A VPN adds wrapping. A cafe path that was fine can drop the fat packets. Some sites hang. VoIP chops. Steam looks cursed. That is not a city-count fix and it is not a speed-test screenshot.
Klox does not ship a consumer MTU picker in this essay. The lever that exists is WireGuard versus OpenVPN on /download advanced settings. No clamp-to-N SLA. No custom DNS picker. DNS through the tunnel, IPv6 leak protection, WebRTC leak blocking remain the documented leftovers. Cookies on this site live at /cookie and are not a packet size.
If you wanted protocol speed, that essay is next door. If you wanted an honest lab, that post exists. If you wanted TCP versus UDP, that guide exists. If you wanted the underpass, you have it. Download the apps. Connect. Try the other protocol once if the fat app hangs. Leave the padlock on. The height limit was never the page.
Related Resources
Change protocol before you hunt a slider
KloxVPN is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, yearly from $2.83 a month, 7-day first-purchase money-back. There is no consumer MTU picker in this article. Advanced settings on the apps are the lever. Download if you want that hop.
Download KloxVPNFrequently Asked Questions
KloxVPN Team
Experts in VPN infrastructure, network security, and online privacy. The KloxVPN team has been building and operating VPN services since 2019, providing consumer and white-label VPN solutions to thousands of users worldwide.