Question 1
Check your work VPN interface MTU
Connect your normal work VPN or security software first. Then identify the MTU configured on the route or VPN interface carrying your work traffic. This helps estimate whether your work VPN can operate reliably over another VPN tunnel.
Choose your operating system, run the command, and enter the MTU shown for the applicable route or interface.
macOS: Use Terminal to identify the route-selected interface and its configured MTU.
route -n get 8.8.8.8 | grep -E 'interface:|mtu:'
Enter the number on the mtu: line for the selected interface. With the work VPN active, use the route/interface carrying work traffic.
Windows PowerShell: Find the route selected for 8.8.8.8, then display that interface's MTU.
$route = Find-NetRoute -RemoteIPAddress 8.8.8.8 | Select-Object -First 1; Get-NetIPInterface -InterfaceIndex $route.InterfaceIndex -AddressFamily IPv4 | Select-Object InterfaceAlias,InterfaceIndex,AddressFamily,NlMtuBytes
Enter the NlMtuBytes number for the returned interface. This reads settings only; it does not change MTU or other network settings.
Linux: Use the selected route to identify the device, then show its configured MTU.
dev=$(ip -4 route get 8.8.8.8 | awk '{for (i=1;i<=NF;i++) if ($i=="dev") {print $(i+1); exit}}'); ip -o link show dev "$dev"
Enter the number after mtu for the returned device. With the work VPN active, verify the selected route is the VPN/tunnel path when applicable.
Using a split-tunnel work VPN? A public destination such as 8.8.8.8 may bypass the corporate VPN. Use a work destination known to travel through the VPN, or identify the VPN/tunnel interface directly.
This locally reported interface MTU is used for the compatibility assessment. It is different from an end-to-end path MTU measurement.
MTU is a tuning value, not a score. Lower values can improve compatibility on networks with extra encapsulation, while unnecessarily low values may reduce efficiency. The goal is to use the largest MTU that works reliably through the complete connection.
Note: Do not manually lower MTU unless necessary. Unusually low or stacked MTU overrides can cause compatibility issues and may expose an additional network characteristic.
Advanced: Public-endpoint path check
Automatic public-endpoint path check
checking availability…
Supplemental diagnostic. Our server sends ICMP probes to the public endpoint associated with this connection and finds the largest packet size confirmed across that external path. Behind a router, CGNAT gateway, firewall, VPN exit, or exit node, the responder may be a gateway or VPN exit rather than your laptop. This does not measure your VPN interface, routed MTU, or inner tunnel MTU, and it does not determine compatibility by itself.
Confirmed external-path packet size
—
Supplemental public-endpoint result only; it may reflect a gateway or VPN exit, not your routed/VPN MTU.
Technical details
Public-endpoint check inconclusive
Advanced/manual MTU troubleshooting