Checking Path MTU with Linux tracepath: Using pmtu in addition to routing for troubleshooting

Linux・CLI・DevOpsカテゴリを表すパンダのイラスト Linux / CLI / DevOps

About This Article
This article was created using an automated generation workflow powered by generative AI. After reviewing the iputils tracepath primary documentation, it outlines how to locate Path MTU (PMTU) for Linux, going beyond the traceroute-like route display.

Verification Status: 📘 tracepath official specification verified, actual traffic unverified
Information Verification Date: October 5, 2026

When experiencing issues such as "communication works, but only large packets stall midway" or "specific sites are unstable over a VPN," not only the route, but alsoPath MTUserves as a useful clue.

Linux tracepath traces the route to the destination while displaying the MTU information discovered along that path.

Running tracepath Directly

tracepath example.com

According to the iputils manual, tracepath is described as a tool that traces the network path to the destination while inspecting the MTU along that path.

It is similar to traceroute, but typically does not require superuser privileges.

What is Path MTU?

MTU is the upper limit of the IP packet size that can be sent at one time.

However, just because your NIC's MTU is 1500 does not mean that 1500 bytes can pass through every segment of the path to the destination.

Along the way,

  • VPN

  • tunnels

  • PPPoE

  • Cloud connection

  • Specialized network equipment

and similar setups may require a smaller MTU somewhere along the path.

The maximum size that can pass from source to destinationis considered the Path MTU.

flowchart LR
    A["PC<br>MTU 1500"] --> B["Router<br>1500"]
    B --> C["VPN/Tunnel<br>1420"]
    C --> D["Internet<br>1500"]
    D --> E["Server"]
    C --> F["Path MTUは小さい区間の影響を受ける"]

Checking the output for pmtu

Although the output varies depending on the environment, in tracepath pmtuchanges and the final summary serve as clues.

Instead of memorizing the static output of an article as the correct answer, on your own path, you should check:

  • how many hops are visible

  • whether the pmtu changes along the way

  • what value is displayed at the end

Check these items.

Disabling name resolution with -n

tracepath -n example.com

-nUsing this option avoids DNS name resolution in hop displays, allowing you to check primarily with numeric addresses.

This is also useful for isolating whether slow path display is caused by the network itself or by reverse DNS name resolution.

Separating IPv4 and IPv6 checks

tracepath -4 example.com
tracepath -6 example.com

In dual-stack environments, the routes for IPv4 and IPv6 may differ.

Even for the same hostname,

  • Stable on IPv4

  • Only the IPv6 route is different

  • Only one side is unreachable

You can isolate issues like this.

How is it different from traceroute?

Both can observe routes, but tracepathalso features Path MTU Discovery as a primary objectiveas its characteristic.

Target to viewView with tracepath
RouteHop
Numeric addresses only-n
IPv4 fixed-4
IPv6 fixed-6
MTU along the pathpmtu

If you only remember it as a "replacement for traceroute," you will overlook the value of viewing PMTU.

Try changing only one parameter

First,

tracepath example.com

After executing this, next, change to

tracepath -n example.com

to change.

Instead of the path itself, we look at how name resolution affects display and latency.

Furthermore, separating IPv4 and IPv6 allows you to track changes one by one.

Do not determine PMTU issues using tracepath alone

Even if a small PMTU is observed with tracepath, do not conclude that it is the cause of the failure based on that alone.

In practical operations,

  • interface MTU

  • VPN/Tunnel configuration

  • ICMP-related filters

  • TCP MSS

  • Actual communication size that fails

  • IPv4/IPv6 differences

  • Firewall/Load Balancer/CDN

are checked together.

Devices along the path may not respond, so not all hops are necessarily visible.

Common symptom where only small packets pass

For example,

  • ping succeeds

  • DNS resolution also succeeds

  • Small HTTP responses pass through.

  • If only large uploads or specific TLS communications stall,

this cannot be explained by simple "connectivity/no connectivity" scenarios.

PMTU and MSS serve as indicators to investigate such size-dependent issues.

Privilege Characteristics

The iputils tracepath manual states that while it is similar to traceroute, it typically does not require superuser privileges.

The ability to run troubleshooting without assuming sudo privileges from the start makes it user-friendly.

However, package configurations and installation states vary depending on the distribution.

Daily-Code-Samples

We provide a script that passes the target host as an argument and sequentially tests standard display and -n.

Official Documentation

Document information

Article title
Checking Path MTU with Linux tracepath: Using pmtu in addition to routing for troubleshooting
Published
Updated
Source
https://papanda925.com/?p=17985&lang=en

License: Text and original figures for which this site holds the relevant rights are available under CC BY 4.0 , unless otherwise noted. This article may include content created or edited with generative AI. If code has a separate license notice or a linked GitHub repository license, that license takes precedence for the code. Quotations, third-party materials, images, and trademarks are excluded from this license. Usage policy

Copied title and URL