<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Networking on Will Riches</title><link>https://www.rich.es/blog/tag/networking/</link><description>Recent content in Networking on Will Riches</description><generator>Hugo</generator><language>en-GB</language><copyright>Copyright © 2025, Will Riches.</copyright><lastBuildDate>Sat, 03 Oct 2026 00:00:00 +0000</lastBuildDate><follow_challenge><feedId>00000000000000000</feedId><userId>00000000000000000</userId></follow_challenge><atom:link href="https://www.rich.es/blog/tag/networking/index.xml" rel="self" type="application/rss+xml"/><item><title>Getting a full 1500-byte MTU on Vodafone FTTP on Openreach Network</title><link>https://www.rich.es/blog/getting-a-full-1500-byte-mtu-on-vodafone-fttp-on-openreach-network/</link><pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate><guid>https://www.rich.es/blog/getting-a-full-1500-byte-mtu-on-vodafone-fttp-on-openreach-network/</guid><description>&lt;p>I run Vodafone FTTP over Openreach with a MikroTik RB5009 and OpenWrt. I&amp;rsquo;d left the MTU at Vodafone&amp;rsquo;s recommended 1492, but wondered whether I could get the full 1500. I hadn&amp;rsquo;t seen Vodafone advertise support for it, so I wasn&amp;rsquo;t sure what to expect.&lt;/p>
&lt;p>PPPoE normally uses eight bytes of a 1500-byte Ethernet payload, leaving 1492 for the IP packet. &lt;a href="https://www.rfc-editor.org/rfc/rfc4638.html">RFC 4638&lt;/a> allows a larger payload if both ends and the Ethernet link support it. Set the Ethernet MTU to 1508, and there&amp;rsquo;s room for a full 1500-byte IP packet plus the PPPoE and PPP headers. These slightly larger frames are often called mini jumbo frames, or baby jumbo frames. My router supported them; Vodafone&amp;rsquo;s side was the unknown.&lt;/p>
&lt;p>The first attempt took the internet down. I rolled back, waited for it to return, and looked at the negotiation. Vodafone had actually accepted the 1500-byte payload. The failure was down to the old PPPoE connection not closing cleanly: new connection requests went unanswered until Vodafone cleared the old session.&lt;/p>
&lt;p>For the retry, I brought PPPoE down cleanly before changing the Ethernet settings, with a backup and automatic rollback ready. It connected in about six seconds. OpenWrt showed 1508 on Ethernet and 1500 on PPPoE, and the router could send and receive full-sized IPv4 and IPv6 packets.&lt;/p>
&lt;p>Then came the odd bit: large IPv6 pings from my PC failed, while smaller pings and web traffic worked. The LAN IPv6 MTU was still 1492, and Windows had learned that value too. It was fragmenting the large packets before they even reached the router.&lt;/p>
&lt;p>The automatic rollback kicked in while I was figuring that out. I reapplied the WAN settings, set the LAN bridge&amp;rsquo;s IPv6 MTU to 1500, and refreshed the router advertisements. Windows picked up the new value and the large pings worked. With the checks passing, I cancelled the rollback.&lt;/p>
&lt;p>So my Vodafone line now carries &lt;strong>1500-byte IP packets over PPPoE for both IPv4 and IPv6&lt;/strong>, including traffic from the LAN. I&amp;rsquo;ve kept it that way. Any efficiency gain is small: the headers are still there, the Ethernet frames are larger, and I haven&amp;rsquo;t measured a speed improvement. Mostly, I wanted to see whether 1492 was really the limit. On my connection, it isn&amp;rsquo;t.&lt;/p>
&lt;h2 id="the-configuration-i-ended-up-with">The configuration I ended up with&lt;/h2>
&lt;p>I tested this on 3 October 2026, using OpenWrt 25.12.5 on the RB5009. PPPoE runs directly on &lt;code>p1&lt;/code>, the Ethernet port connected to the ONT.&lt;/p>
&lt;table>
&lt;thead>
&lt;tr>
&lt;th>Layer&lt;/th>
&lt;th>Device on my router&lt;/th>
&lt;th style="text-align:right">MTU&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Ethernet connection to the ONT&lt;/td>
&lt;td>&lt;code>p1&lt;/code>&lt;/td>
&lt;td style="text-align:right">1508&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>PPPoE IP interface&lt;/td>
&lt;td>&lt;code>pppoe-wan&lt;/code>&lt;/td>
&lt;td style="text-align:right">1500&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>LAN IPv6&lt;/td>
&lt;td>&lt;code>br-lan&lt;/code>&lt;/td>
&lt;td style="text-align:right">1500&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table>
&lt;p>In &lt;code>/etc/config/network&lt;/code>, I added a device section for the WAN Ethernet port:&lt;/p>
&lt;pre tabindex="0">&lt;code class="language-uci" data-lang="uci">config device &amp;#39;wan_mini_jumbo&amp;#39;
 option name &amp;#39;p1&amp;#39;
 option mtu &amp;#39;1508&amp;#39;
&lt;/code>&lt;/pre>&lt;p>Use your own WAN port name. If it already has a device section, add the MTU there.&lt;/p>
&lt;p>In the existing &lt;code>wan&lt;/code> interface section:&lt;/p>
&lt;pre tabindex="0">&lt;code class="language-uci" data-lang="uci"> option mtu &amp;#39;1500&amp;#39;
&lt;/code>&lt;/pre>&lt;p>OpenWrt&amp;rsquo;s &lt;a href="https://github.com/openwrt/openwrt/blob/openwrt-25.12/package/network/services/ppp/files/ppp.sh">PPPoE setup script&lt;/a> passes this value to &lt;code>pppd&lt;/code> as both the MTU and MRU.&lt;/p>
&lt;p>For LAN IPv6, in the existing &lt;strong>device section named &lt;code>br-lan&lt;/code>&lt;/strong>:&lt;/p>
&lt;pre tabindex="0">&lt;code class="language-uci" data-lang="uci"> option mtu6 &amp;#39;1500&amp;#39;
&lt;/code>&lt;/pre>&lt;p>After applying the settings, I refreshed the advertisements:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>/etc/init.d/odhcpd restart
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>By default, &lt;a href="https://github.com/openwrt/odhcpd/blob/5d7be43f/src/config.c">odhcpd&lt;/a> takes the advertised MTU from the interface&amp;rsquo;s IPv6 configuration.&lt;/p>
&lt;p>The RB5009&amp;rsquo;s internal DSA conduit, &lt;code>eth0&lt;/code>, automatically increased to 1512.&lt;/p>
&lt;p>Merge these changes into your existing configuration. The key for me was running &lt;code>ifdown wan&lt;/code> before changing Ethernet settings, then explicitly bringing WAN back up afterwards. Rolling back also needed that last step; restoring the file alone didn&amp;rsquo;t reconnect it.&lt;/p>
&lt;h2 id="how-i-tested-it">How I tested it&lt;/h2>
&lt;p>I checked negotiation, traffic from the router, and traffic forwarded from the PC. As a baseline, 1492-byte IPv4 packets passed before the changes. At 1500 with fragmentation prohibited, the router reported &lt;code>Message too large&lt;/code>; tests from the PC got a fragmentation-required response.&lt;/p>
&lt;p>On the successful connection, Vodafone&amp;rsquo;s PADO and PADS replies contained &lt;code>PPP-Max-Payload 0x05DC&lt;/code>. That&amp;rsquo;s 1500 in decimal, confirming acceptance of the larger payload.&lt;/p>
&lt;p>I checked the live interface values on OpenWrt with:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>cat /sys/class/net/p1/mtu
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>cat /sys/class/net/pppoe-wan/mtu
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>cat /proc/sys/net/ipv6/conf/br-lan/mtu
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>These returned 1508, 1500 and 1500. On Windows, I also checked the IPv6 MTU:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-powershell" data-lang="powershell">&lt;span style="display:flex;">&lt;span>Get-NetIPInterface -InterfaceAlias &lt;span style="color:#e6db74">&amp;#39;Ethernet&amp;#39;&lt;/span> -AddressFamily IPv6 |
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span> Select-Object InterfaceAlias, NlMtu
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>I temporarily installed &lt;code>iputils-ping&lt;/code> and &lt;code>tcpdump&lt;/code>. The bundled BusyBox ping lacked &lt;code>-M do&lt;/code>, needed to prohibit IPv4 fragmentation.&lt;/p>
&lt;p>For IPv4, 1472 bytes of data plus 28 bytes of IP and ICMP headers makes a 1500-byte packet. From the router:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>ping -4 -I pppoe-wan -M &lt;span style="color:#66d9ef">do&lt;/span> -s &lt;span style="color:#ae81ff">1472&lt;/span> -c &lt;span style="color:#ae81ff">100&lt;/span> -i 0.05 1.1.1.1
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>IPv6 needs 1452 bytes of data plus 48 bytes of headers. Use a current global IPv6 address assigned to the router from the ISP&amp;rsquo;s delegated prefix:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-sh" data-lang="sh">&lt;span style="display:flex;">&lt;span>ping -6 -I YOUR_ROUTER_GLOBAL_IPV6_ADDRESS -M &lt;span style="color:#66d9ef">do&lt;/span> -s &lt;span style="color:#ae81ff">1452&lt;/span> -c &lt;span style="color:#ae81ff">100&lt;/span> -i 0.05 2001:4860:4860::8888
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Then from Windows, replacing the placeholders with the PC&amp;rsquo;s home Ethernet addresses:&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-powershell" data-lang="powershell">&lt;span style="display:flex;">&lt;span>ping.exe &lt;span style="color:#ae81ff">-4&lt;/span> -S YOUR_LAN_IPV4_ADDRESS &lt;span style="color:#f92672">-f&lt;/span> -l &lt;span style="color:#ae81ff">1472&lt;/span> -n &lt;span style="color:#ae81ff">5&lt;/span> &lt;span style="color:#ae81ff">1.1&lt;/span>.1.1
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>ping.exe &lt;span style="color:#ae81ff">-6&lt;/span> -S YOUR_CURRENT_LAN_IPV6_ADDRESS -l &lt;span style="color:#ae81ff">1452&lt;/span> -n &lt;span style="color:#ae81ff">5&lt;/span> &lt;span style="color:#ae81ff">2001&lt;/span>&lt;span style="color:#960050;background-color:#1e0010">:&lt;/span>&lt;span style="color:#ae81ff">4860&lt;/span>&lt;span style="color:#960050;background-color:#1e0010">:&lt;/span>&lt;span style="color:#ae81ff">4860&lt;/span>::&lt;span style="color:#ae81ff">8844&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>Binding the tests to the home connection and capturing traffic on the WAN confirmed it crossed the Vodafone link. The capture also caught an easy trap: Windows can fragment IPv6 pings itself, so a reply alone doesn&amp;rsquo;t prove a full 1500-byte packet made it through. The final capture showed unfragmented requests and replies for both IP versions.&lt;/p>
&lt;table>
&lt;thead>
&lt;tr>
&lt;th>Final verification&lt;/th>
&lt;th>Result&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>100 router-originated 1500-byte IPv4 ping exchanges&lt;/td>
&lt;td>100 replies, no loss&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>100 router-originated 1500-byte IPv6 ping exchanges&lt;/td>
&lt;td>100 replies, no loss&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Five PC-originated 1500-byte exchanges per IP version&lt;/td>
&lt;td>All ten passed through the router&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>WAN capture of those 210 exchanges&lt;/td>
&lt;td>420 packets, all carrying unfragmented 1500-byte IP packets&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>HTTPS downloads from the PC over the home connection&lt;/td>
&lt;td>1,000,000 bytes for each IP version&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>DNS through AdGuard Home&lt;/td>
&lt;td>Passed&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table>
&lt;p>This worked on my line and equipment. Other Vodafone connections may behave differently, and some internet paths will still have a smaller MTU. If you try it, the checks above should help establish what your own line can do.&lt;/p></description></item></channel></rss>