한국어English日本語简体中文繁體中文DeutschไทยTiếng ViệtРусскийPortuguês (Brasil)EspañolBahasa Indonesia

Game Lag White Paper › L5 Data center network equipment

MTU mismatch (only large packets vanish) MTU black hole

Cause ID dc-mtu · Primary owner Infra team (Network infrastructure) · Also Infra team (Server infrastructure), Game team (Server development)

Open the interactive card with figures and simulations →

If the MTU (the largest size that can be sent at once) shrinks somewhere along the path and the “packet too big” messages are blocked, only large packets keep vanishing.

Why The MTU shrinks on a tunnel or VPN segment → Effect A firewall blocks the “packet too big” messages (ICMP), so the sender never finds out → On screen Freezes and then disconnects only when opening large screens such as the inventory or character list

Symptoms
Freeze, Disconnect, Can’t connect / infinite loading
Factors
Packet loss
Who’s affected
Specific region/ISP, Just me
When
During specific actions, Right after login or maintenance
Owner
Primary owner Infra team (Network infrastructure) · Also Infra team (Server infrastructure), Game team (Server development)
Game team action items
To lower it directly on the server side, set the socket’s maximum segment size with TCP_MAXSEG (splitting messages into smaller pieces in game code alone won’t prevent it), keep UDP packets at 1,200 bytes or less.
Infra team action items
Network: reduce TCP packet size on tunnel segments (MSS clamping), allow “packet too big” messages (ICMP) through firewalls and cloud network ACLs. Servers/OS: allow “packet too big” messages (ICMP) in server firewalls and cloud security groups too, turn on MTU probing in the server kernel (tcp_mtu_probing=1) as a last safety net that only kicks in after a freeze of a few seconds.
Ballpark numbers
Usually 1,500 bytes, shrinking to around 1,400 through a tunnel.
On the graph
Outliers only · Disconnects by region/ISP, failed large responses
Where to look
From the affected player’s PC, ping the server with the don’t-fragment flag (DF) set, varying the size. On Windows, ping /f /l 1472 SERVER_IP; on Linux, ping -M do -s 1472 SERVER_IP (1,472 is the 1,500 MTU minus the 20-byte IP header and the 8-byte ICMP header). Lower the size step by step to find the largest size that gets through, and check whether the server-side security groups and firewalls allow ICMP “packet too big” messages (Fragmentation Needed)
Confirmed if
Small pings get through but the 1,472-byte DF ping fails (no reply, or an error saying fragmentation is needed), and the largest size that passes is small, around 1,400. Players in the same region freeze only when opening large screens
Ruled out if
The 1,472-byte DF ping also gets through: not a path MTU problem. Even small pings fail: ICMP itself is blocked, so this method can’t tell
Check with
The player’s own environment

Sources

  1. RFC 2923: TCP Problems with Path MTU Discovery IETF
    If a firewall blocks ICMP (Fragmentation Needed), path MTU discovery fails and only large packets keep vanishing (black hole); pings and small messages still work, which makes it hard to diagnose
  2. Maximum transmission unit and maximum segment size Cloudflare
    Internet path MTU 1,500, 1,476 through a GRE tunnel; limiting TCP MSS to 1,436 or less is recommended
  3. IP Sysctl Linux kernel
    tcp_mtu_probing=1 is normally off and turns on TCP path MTU probing only when it detects an ICMP black hole
  4. ping(8) — Linux manual page iputils
    -M do sets the DF flag and refuses packets larger than the path MTU; -s sets the data size (default 56 bytes, plus the 8-byte ICMP header)
  5. ping Microsoft
    /f sets the DF flag and is used to find path MTU problems; /l sets the data size

See also

Same layer: L5 Data center network equipment

Same symptom (Freeze), other layers

View the interactive card with figures and simulations