- OpenVPN sends this as an UDP packet, which adds 8 bytes for UDP + 20 or 40 bytes for the IPv4/IPv6 header
- the resulting packet is (no matter how many bytes are added) "larger than 1500 bytes"
- the system now wants to send this resulting UDP packet to the OpenVPN server, and under normal conditions this will be sent over an Ethernet interface with a MTU of 1500
-
- "send a package larger than the MTU of the egress interface" is a well-defined scenario, and so "IP Fragmentation" is used - that is, on the IP layer, the UDP packet OpenVPN has sent is split into 2 smaller IP packets - sometimes "half:half", sometimes "1500:rest", both is allowed
+
- "send a packet larger than the MTU of the egress interface" is a well-defined scenario, and so "IP Fragmentation" is used - that is, on the IP layer, the UDP packet OpenVPN has sent is split into 2 smaller IP packets - sometimes "half:half", sometimes "1500:rest", both is allowed
- theoretically these packets could also hit a router with a PPPoE MTU of 1492 bytes next, splitting a 1500 byte fragment *again*