MikroTik PPPoE MTU and MSS: when some websites do not open
Last updated: 2 October 2026
The customer is connected, most sites work, but a few never load, or pages open without pictures and uploads stall. Over PPPoE that pattern almost always means packets are too big for the link. The fix is one setting.
Why it happens
An ordinary network carries packets of up to 1500 bytes. PPPoE uses 8 of those bytes for itself, so a PPPoE link carries 1492 at most. That figure is the MTU. A full-size packet no longer fits. Normally the sender is told to send smaller ones, but many networks on the internet block that message, and the connection just hangs.
The cure is to make both ends agree on smaller packets from the start. Every TCP connection opens by announcing the largest segment it accepts, the MSS. The router can lower that number as the connection passes. This is called MSS clamping. For an MTU of 1492 the right MSS is 1452.
Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.
On a PPPoE server: the profile setting
/ppp profile print
/ppp profile set [find name=5M] change-tcp-mss=yesWith change-tcp-mss=yes the router adds the clamping rules itself for each customer session, in both directions. Set it on every profile your customers use. Sessions pick it up at the next login.
With a mangle rule
On a router that is a PPPoE client of your provider, clamp what leaves through the PPPoE interface:
/ip firewall mangle add chain=forward protocol=tcp tcp-flags=syn out-interface=pppoe-out1 action=change-mss new-mss=clamp-to-pmtu passthrough=yesclamp-to-pmtu works out the value from the interface the packet leaves through. On a server, where you want every customer session covered by one rule whatever the profile says, use a fixed value instead:
/ip firewall mangle add chain=forward protocol=tcp tcp-flags=syn tcp-mss=1453-65535 action=change-mss new-mss=1452 passthrough=yes comment="pppoe mss"This lowers any MSS above 1452 and leaves smaller ones alone. If your link MTU is lower than 1492, use that MTU minus 40.
max-mtu and max-mru on the server
/interface pppoe-server server print
/interface pppoe-server server set [find service-name=isp] max-mtu=1492 max-mru=1492These cap the packet size the server agrees with each customer. 1492 is right for a plain cable or fibre network. If the path between your router and the customers is itself smaller, as on some wireless links or links that add their own header, use a lower figure such as 1480. To see what a session actually got:
/interface print detail where name~"pppoe"A change applies to new sessions only.
Test with ping
Send a packet of an exact size that is not allowed to be split. From a MikroTik on the customer side, where the size is the whole packet:
/ping 1.1.1.1 size=1492 do-not-fragment count=4
/ping 1.1.1.1 size=1493 do-not-fragment count=4The first should get replies and the second should fail. From a Windows computer the size is the data only, 28 bytes less:
ping -f -l 1464 1.1.1.1
ping -f -l 1465 1.1.1.1If 1464 already fails, lower the number until it passes. The largest size that works, plus 28, is your real MTU. Set max-mtu and the MSS (MTU minus 40) to match.
If sites still do not open
- Nothing opens by name, but ping to 1.1.1.1 works: DNS, not packet size. Check the DNS server in the PPP profile.
- The rule exists but counts nothing: look at
/ip firewall mangle print stats. The interface name in the rule may be wrong. - The customer cannot connect at all: that is a different problem. See PPPoE not connecting.
The basics of both ends are in PPPoE server setup and PPPoE client setup.
Where RadiusNest fits
Packet size is a matter between the router and the line, so nothing about it changes with RadiusNest. Logins, speeds and end dates are checked centrally; MTU and MSS stay as you set them on the router. If your PPPoE customers are checked by RADIUS, the mangle rule above is the simplest way to clamp every session.
Start the free trial See pricing
Questions and answers
What MTU should PPPoE use?
1492 on an ordinary network: 1500 bytes minus the 8 bytes PPPoE needs. Use less only if the link between server and customer is smaller.
What MSS goes with an MTU of 1492?
1452. The MSS is the MTU minus 40 bytes of IP and TCP headers.
Why do only some websites fail?
Sites that send small packets, or whose networks pass the "packet too big" message, work. Sites behind networks that block that message hang.