MTU defines Maximum Transmission Unit. The best MTU router setting affects the client or Server Windows MTU dynamically by lowering it before packets cross tunnels- before the firewall blocks ICMP packets. Firewalls blocking ICMP disable IP's dynamic Path MTU Discovery causing fragmentation at VPN, L2TP tunnels impacting performance. Gateways are not able to respect native DF bit flags (Don't Fragment) because they are isolated on another OSI Model stack interface. The performance hit comes from what I call the "two for one blue light packet special" caused by the overhead of the tunnel header forcing two packets across the tunnel for each originating packet.