Path MTU

 

The smallest MTU of any link on the current path between two hosts.
This may change over time since the route between two hosts, especially on the Internet, may change over time. It is not necessarily symmetric and can even vary for different types of traffic from the same host.

Fragmentation

When a packet is too large to be sent across a link as a single unit, a router can fragment the packet.
This means that it splits it into multiple parts which contain enough information for the receiver to glue them together again. Note that this is not done on a hop-by-hop basis, but once fragmented a packet will not be put back together until it reaches its destination.

Fragmentation is undesirable for numerous reasons, including:

  • If any one fragment from a packet is dropped, the entire packet needs to be retransmitted. This is a very significant problem.
  • It imposes extra processing load on the routers that have to split the packets.
  • In some configuration, simpler firewalls will block all fragments because they don’t contain the header information for a higher layer protocol (eg. TCP) needed for filtering.

DF (Don’t Fragment) bit


This is a bit in the IP header that can be set to indicate that the packet should not be fragmented by routers, but instead an ICMP “can’t fragment” error is returned sent to the sender and the packet is dropped.

ICMP Can’t Fragment Error


This error (type 3 (destination unreachable), code 4 (fragmentation needed but don’t-fragment bit set)) is returned by a router when it receives a packet that is too large for it to forward and the DF bit is set.
The packet is dropped and the ICMP error is sent back to the origin host.

Normally, this tells the origin host that it needs to reduce the size of its packets if it wants to get through. Recent systems also include the MTU of the next hop in the ICMP message so the source knows how big its packets can be.
Note that this error is only sent if the DF bit is set; otherwise, packets are just fragmented and passed through.

MSS

The MSS is the maximum segment size.
It can be announced during the establishment of a TCP connection to indicate to the other end the largest amount of data in one packet that should be sent by the remote system.

Normally the packet generated will be 40 bytes larger than this; 20 bytes for the IP header and 20 for the TCP header. Most systems announce a MSS that is determined from the MTU on the interface that the traffic to the remote system passes out from the system through.

Path MTU Discovery (PMTU-D)

Now you know that Path MTUs vary.
You know that fragmentation is bad.

The solution?

Well, one solution is Path MTU Discovery.

A. The idea behind it is to send packets that are as large as possible while still avoiding fragmentation.

B. A host does this by starting by sending packets that have a maximum size of the lesser of the local MTU or the MSS announced by the remote system.

C. These packets are sent with the DF bit set.

D. If there is some MTU between the two hosts which is too small to pass the packet successfully, then an ICMP can’t fragment error will be sent back to the source. It will then know to lower the size; if the ICMP message includes the next hop MTU, it can pick the correct size for that link immediately, otherwise it has to guess.

Now, to the problem with ICMP filtering and PMTU-D

Many network administrators have decided to filter ICMP at a router or firewall.
There are valid (and many invalid) reasons for doing this, however it can cause problems. ICMP is an integral part of the Internet and can not be filtered without due consideration for the effects.


In this case, if the ICMP can’t fragment errors can not get back to the source host due to a filter, the host will never know that the packets it is sending are too large.

This means it will keep trying to send the same large packet, and it will keep being dropped–silently dropped from the view of any system on the other side of the filter.

While a small handful of systems that implement PMTU-D also implement a way to detect such situations, most don’t and even for those that do it has a negative impact on performance and the network.

Many packet filters will allow you to setup filters to only allow certain types of ICMP messages through.


e.g :

access-list  199 remark Permit Path MTU to function.
access-list 199 permit icmp any any packet-too-big

If you reconfigure them to let ICMP can’t fragment (type 3, code 4) messages through the firewall, the problem should disappear.