How to determine your MTU setting for VPN
This is a Level B document - It contains moderately difficult end-user information.
Sometimes, in Cisco versions 3.x, you are unable to connect to certain servers (usually a Lotus Notes mail server, or Planet PeopleSoft) because your "MTU" setting is too high. "MTU" stands for "Maximum Transmission Unit" - which is how data packets are assembled across network connections. If your MTU setting is too high, your data packets will be fragmented and dropped, and you will be unable to connect to some servers.
Note: As of October 7, 2004, Cisco VPN Client version 4.0.4(D) is the standard supported version of VPN client software. If you are still on an earlier version, please update your software as soon as possible. See Eureka! document 54102 — Upgrade or install Cisco VPN Client software. To find out what version of the Cisco VPN software you are running, see Eureka! document 55175 — How to tell what version of Cisco VPN software you are using.
NOTE: The MTU in Cisco version 4.0.x generally does NOT need to be reset. You should not need to touch the settings if you are running version 4.0.x, unless it is at the advice of Technical Support Operations, or you were referred to this document to troubleshoot an issue.
To find the optimal MTU setting for your machine, please follow the steps below. Be sure to look at the screenshots carefully - they may look similar, but are different in contents.
NOTE: You MUST be logged in for this test to work.
Click the Start menu, then Run..., and type in cmd in the Open: field.
Note: If you get the message " Request timed out." 4 times, make sure you have already connected to the PeopleSoft network via VPN.
If you get the following screen (MTU good - a ping reply), click here for more instructions:
If your MTU number you are testing is too high, the message reads " Packet needs to be fragmented but DF set." If you are getting that message, follow these steps:
If you are at the same DOS prompt, hit your {
Up Arrow} key and your previous DOS command appears.
Example: If you started with 1432, but you got a bad response, hit the {
Up Arrow} key, then back space over the 1432 and type in "1372". The command would now read:
ping planet.peoplesoft.com -f -l 1372.
Press {
Enter} to execute this new command.
View the results you get. If you are still getting the "
Packet needs to be fragmented but DF set" message, you can hit your {
Up Arrow} key again to edit the DOS command to drop the number by another 100 (e.g.,
ping planet.peoplesoft.com -f -l 1272. )
As long as you continue to get the " Packet needs to be fragmented but DF set." message, keeping lowering the number by 100. The number may go as low as about 572 or even lower.
Keep trying until you get the following screen (a ping reply):
For instructions on how to change the MTU setting, see Eureka! document 54112 — Lotus Notes or Planet inaccessible via VPN.
** Note: This method gives you a good estimate of the number to use. If you would like to fine tune the result, you can change the number you use to ping until you find the highest number that gives you a ping response. Then add 28 to that figure. Often, the result you get using the numbers in this document is exactly right, so further testing is not necessary.
Click here to go back to the beginning of this document.
Created by the PeopleSoft Knowledge Management Team.
Copyright © 2004
All rights reserved.
Created: kcw 04/24/2003
Revised: pmg 11/23/2004
Reviewed: 09/28/2004