Networking-Blog

My WordPress Blog

Windows MTU Ping Test

MTU Ping Test

A series of ping tests using the command, ping www.expedient.net -f -l xxxx, where xxxx is the packet size, can be used to determine the optimal MTU for your connection.

  1. Go to Start and select Run.
  2. Type in cmd (Windows 2000/XP) or command (Windows 98/ME) into the Open: field. Hit the enter key or click OK. The DOS prompt should open.
  3. At the DOS prompt, type in ping www.expedient.net -f -l 1492 and hit the Enter key.
  4. Note the results above indicate that the packet needs to be fragmented. Lower the size the packet in increments of +/-10 (e.g. 1472, 1462, 1440, 1400) until you have a packet size that does not fragment.
  5. Begin increasing the packet size from this number in small increments until you find the largest size that does not fragment. Add 28 to that number (IP/ICMP headers) to get the optimal MTU setting. For example, if the largest packet size from ping tests is 1462, add 28 to 1462 to get a total of 1490 which is the optimal MTU setting.
  6. Change the MTU using DrTCP or editing the registry. See MTU Settings for further information.

Windows MTU

MTU in more detail:

The MTU setting is a definition of how much data you can transmit in one go before it has to be cut-up or fragmented. Every connection has a limit and can be determined using a simple command in DOS.

The value you should use for your MTU setting is dependant on the MTU value for your ISP since all packets (data) will be travelling through their servers.

To determine the maximum MTU value for your ISP, open a DOS window and type :

ping -f -l [packetsize] [www.your_isp_url.com]

Where [packetsize] is the amount of data you want to send (range is 0 – 1500) and [www.your_isp_url.com] is the url of your ISP.

Your ISP’s MTU is determined from the larest packetsize value that does not return the error “Packet needs to be fragmented but DF set” -28 (20 bytes for the IP and 8 bytes for the ICMP header). This is dependant on how the server is configired, but essentially the result is the same.

For example:

C:WINDOWS>ping -f -l 1472 192.168.1.10

Pinging 192.168.1.10 with 1472 bytes of data:

Reply from 192.168.1.10: bytes=1472 time=2ms TTL=128
Reply from 192.168.1.10: bytes=1472 time=1ms TTL=128
Reply from 192.168.1.10: bytes=1472 time=1ms TTL=128
Reply from 192.168.1.10: bytes=1472 time=1ms TTL=128

Ping statistics for 192.168.1.10:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 1ms, Maximum = 2ms, Average = 1ms

The maximum packet size I could send to my gateway system without it fragmenting was 1472. This means that an MTU value of 1500 is fine for my ethernet connection (1472 + 28 = 1500).

As you can see from the example above, you can determine MTU value for you LAN systems also, as this is dependant on the potential bottle neck that is the gateway system. All packets have to pass through that, so the MTU value for your gateway limits the MTU value for your LAN systems.

Summary:

What are RWIN (TCP Receive Window) and MTU?

What is Rwin?

RWIN (or TCP receive window) is the amount of data that your PC can accept without acknowledging the user.
When a sender sends a packet to the user, it requires an acknowledgement from the receiving system. If this ACK is not received, it will wait for a certain amount of time, and then retransmit. This is how TCP is made reliable.
This start-stop process slows down transmission, but to enable a speedier process, you can set the size of the receiving window so as to sustain a continuous data transfer.
By default, this window is too small for many types of DSL and Cable (8192 for Windows 95/98/98SE/NT and 16384 for Windows ME/2000).
Increasing the Rwin setting, will allow more information to be transferred non-stop, up to a point, and then after this point, no difference will be noticed for the particular connection. The point will vary depending on bandwidth * delay. This is why you should allocate more than you actually need. I use a value of 65535.

What is MTU?

MTU is short for Maximum Transmission Unit, the largest physical packet size, measured in bytes, that a network can transmit. Any messages larger than the MTU are divided into smaller packet before being sent.
In order to transmit the most amount in one go, you should set your MTU to a high value. I use a value of 1500.
If your MTU is low, then it will take more packets to transmit the same amount of data as a higher valued MTU, thus taking more time.

How do I use DrTCP and what does it do?

Firstly, I would like to start by explaining that Dr TCP is not a patch… it is purely a shortcut to registry editing. It does nothing without user intervention.

All information has been grabbed from www.dslreports.com and assumes that you are using Win98/98SE/ME/2000.
Dr. TCP

TCP Receive Window: This is where you set the Rwin. This is the single most important tweak, and raising the value from the Windows default will greatly improve download speeds. My Rwin is set to 65535.

Windows Scaling: 65535 is the highest value that you can set your Rwin to, without having to use windows scaling. Scaling is needed to enter any number higher than 65535. Most users do not need a higher Rwin that 65535, and so I recommend that this setting be set to default ( off).

Time Stamping: This setting may or may not improve performance. If you have a line where latency varies a lot, time stamping may be beneficial…….experiment with it to make sure. I have my setting at default ( off).

Selective Acks: This improves the speed of lines that tend to lose packets (packet loss), by re-transmitting only packets that were lost, if any. I have my setting at default ( on).

Path MTU Discovery: This automatically sets your MTU to suit the type of line that you have (dial-up or broadband). The highest MTU that you can set is 1500. I have mine set to default ( on).

Black Hole Detection: This discovers routers on the web that cause MTU Discovery to work sub-optimally. I have mine set to default ( off).

Max. Duplicate ACKs: This allows for faster re-transmission of packets when lost. I leave this setting blank. (blank = 3 for Win98/98SE/ME and blank = 2 for Win2000).

TTL: Time To Live is the amount of hops (servers) that a transmission packet will take before all packets are lost. If you were receiving packets from 20 hops away, and your TTL was set to 19 or less, then all packets would be lost before they reach you. I leave this setting blank (blank = 128 in Win98/98SE/ME/2000).

Adapter Settings: This is where you set your MTU. I have mine set to 1500 for both NIC and Dial-up.

ICS Settings: If you use Internet Connection Sharing (a Microsoft program), then you should set the ICS MTU to the same as that of the PC. This is grayed out if ICS is not being used.

When you are happy with your settings, you need to hit the Apply tab (you may need to hit tab to highlight it). Next click on Exit and then reboot the PC. A reboot is necessary to activate the settings.

An ADSL connection into your premises (office or home) is technically a dedicated line between you and your telephone exchange. However, from your telephone exchange to the ISP’s network, your data would be traveling over a network that is shared between you and other ADSL users.

The speed that you would get would fluctuate depending upon how many users are connected to the network (“contending” for the bandwidth available) at any point in time.

The contention ratio reflects the amount of bandwidth actually available to all the customers versus the maximum bandwidth all of the customers could attempt to use at the same time.

Each Pipe carries a 10Mb capacity, this is the contended bandwidth, it’s not 50 people connected to a 512K pipe. It 50 people connected to a 10Mb pipe.

A contention ratio of 1 would mean that you would always be able to send or receive at the maximum data rate because there is no other user sharing the bandwidth with you, a contention ratio of 50 means that it is possible that you can only send or receive at 1/50th of the pipe capacity because you are sharing the bandwidth with 50 other people.

If you do the sums :

10,000,000 / 50 = 200,000

So the worst-case scenario would be 200K/sec connection.

Statistically, most users do not use their full bandwidth most of the time, so the worst case seldom if ever occurs. The general rule is: the lower the contention ratio, the more likely you are to continue to get fast throughput during busy times. However, because of the “bursty” nature of Internet traffic, it is unlikely that the worst-case scenario will come about.

Linux MTU

sudo ip link set eth0 mtu 1500
!
sudo ifconfig
!

Enable MTU Path Discovery:

sudo vi /etc/sysctl.conf
!
# Path Maximum Transfer Unit discovery–disable this and the MTU settings are derived
# from the MTUs of all the hops along the# path to the host you are connecting to,
# including the host itself; 1 enables, 0 disables
net.ipv4.ip_no_pmtu_disc = 1

Allow MTU Path Discovery through the firewall :

sudo iptables -I FORWARD 7 -i eth0 -p tcp –tcp-flags SYN,RST SYN -j TCPMSS –clamp-mss-to-pmtu
sudo iptables -I OUTPUT 7 -i eth0 -p tcp –tcp-flags SYN,RST SYN -j TCPMSS –clamp-mss-to-pmtu

Path MTU Discovery and Filtering ICMP

Path MTU

 

The smallest MTU of any link on the current path between two hosts.
This may change over time since the route between two hosts, especially on the Internet, may change over time. It is not necessarily symmetric and can even vary for different types of traffic from the same host.

Fragmentation

When a packet is too large to be sent across a link as a single unit, a router can fragment the packet.
This means that it splits it into multiple parts which contain enough information for the receiver to glue them together again. Note that this is not done on a hop-by-hop basis, but once fragmented a packet will not be put back together until it reaches its destination.

Fragmentation is undesirable for numerous reasons, including:

  • If any one fragment from a packet is dropped, the entire packet needs to be retransmitted. This is a very significant problem.
  • It imposes extra processing load on the routers that have to split the packets.
  • In some configuration, simpler firewalls will block all fragments because they don’t contain the header information for a higher layer protocol (eg. TCP) needed for filtering.

DF (Don’t Fragment) bit


This is a bit in the IP header that can be set to indicate that the packet should not be fragmented by routers, but instead an ICMP “can’t fragment” error is returned sent to the sender and the packet is dropped.

ICMP Can’t Fragment Error


This error (type 3 (destination unreachable), code 4 (fragmentation needed but don’t-fragment bit set)) is returned by a router when it receives a packet that is too large for it to forward and the DF bit is set.
The packet is dropped and the ICMP error is sent back to the origin host.

Normally, this tells the origin host that it needs to reduce the size of its packets if it wants to get through. Recent systems also include the MTU of the next hop in the ICMP message so the source knows how big its packets can be.
Note that this error is only sent if the DF bit is set; otherwise, packets are just fragmented and passed through.

MSS

The MSS is the maximum segment size.
It can be announced during the establishment of a TCP connection to indicate to the other end the largest amount of data in one packet that should be sent by the remote system.

Normally the packet generated will be 40 bytes larger than this; 20 bytes for the IP header and 20 for the TCP header. Most systems announce a MSS that is determined from the MTU on the interface that the traffic to the remote system passes out from the system through.

Path MTU Discovery (PMTU-D)

Now you know that Path MTUs vary.
You know that fragmentation is bad.

The solution?

Well, one solution is Path MTU Discovery.

A. The idea behind it is to send packets that are as large as possible while still avoiding fragmentation.

B. A host does this by starting by sending packets that have a maximum size of the lesser of the local MTU or the MSS announced by the remote system.

C. These packets are sent with the DF bit set.

D. If there is some MTU between the two hosts which is too small to pass the packet successfully, then an ICMP can’t fragment error will be sent back to the source. It will then know to lower the size; if the ICMP message includes the next hop MTU, it can pick the correct size for that link immediately, otherwise it has to guess.

Now, to the problem with ICMP filtering and PMTU-D

Many network administrators have decided to filter ICMP at a router or firewall.
There are valid (and many invalid) reasons for doing this, however it can cause problems. ICMP is an integral part of the Internet and can not be filtered without due consideration for the effects.


In this case, if the ICMP can’t fragment errors can not get back to the source host due to a filter, the host will never know that the packets it is sending are too large.

This means it will keep trying to send the same large packet, and it will keep being dropped–silently dropped from the view of any system on the other side of the filter.

While a small handful of systems that implement PMTU-D also implement a way to detect such situations, most don’t and even for those that do it has a negative impact on performance and the network.

Many packet filters will allow you to setup filters to only allow certain types of ICMP messages through.


e.g :

access-list  199 remark Permit Path MTU to function.
access-list 199 permit icmp any any packet-too-big

If you reconfigure them to let ICMP can’t fragment (type 3, code 4) messages through the firewall, the problem should disappear.

Cisco Maximum Transmission Unit (MTU)

(TCP, IP, MTU and MSS magic numbers)

1500 The biggest-sized IP packet that can normally traverse the Internet without getting fragmented. Typical MTU for non-PPPoE, non-VPN connections.
1492 The maximum MTU recommended for Internet PPPoE implementations.
1472 The maximum ping data payload before fragmentation errors are received on non-PPPoE, non-VPN connections.
1460 TCP Data size (MSS) when MTU is 1500 and not using PPPoE.
1464 The maximum ping data payload before fragmentation errors are received when using a PPPoE-connected machine.
1452 TCP Data size (MSS) when MTU is 1492 and using PPPoE.
576 Typically recommended as the MTU for dial-up type applications, leaving 536 bytes of TCP data.
48 The sum of IP, TCP and PPPoE headers.
28 The sum of IP and ICMP headers.

Reduce 1472 by 10 until you no longer get the “packet needs to be fragmented” error message.
Then increase by 1 until you are 1 less away from getting the “packet need to be fragmented” message again.

Add 28 more to this (since you specified ping packet size, not including IP/ICMP header of 28 bytes),
and this is your MaxMTU.

Note: If you can ping through with the number at 1472, you are done! Stop right there.

Add 28 and your MaxMTU is 1500.

For PPPoE, your MaxMTU should be no more than 1492 to allow space for the 8 byte PPPoE “wrapper,”
but again, experiment to find the optimal value.
For PPPoE, the stakes are high: if you get your MTU wrong, you may not just be sub-optimal, things like
UPLOADING or web pages may stall or not work at all!