The Packet Capture That Looked Perfect and Was Lying to Me
A remote-desktop client's 'cannot create tunnel' error came with genuinely compelling MTU/MSS evidence pointing at a network black hole — evidence that was real, reproducible, and completely unrelated to the actual failure.
This article is also available in Traditional Chinese: 中文版 — same content, just a language difference.
One machine could connect to a corporate VDI/remote-desktop service; an otherwise-identical one, on a different network segment, couldn't — same account, same server, "cannot create tunnel." The diagnostic trail pointed hard at a classic MTU/MSS black hole: real packet loss at specific sizes, a real dropped TCP segment in a capture. All of it checked out. None of it was the actual cause.
What the evidence actually said
Large ICMP pings above a certain size failed outright; below it, they succeeded cleanly. A packet capture had already shown a specific TCP segment getting lost mid-handshake on an earlier attempt. Cloudflare WARP was active on the affected machine's DNS resolver output, which made "traffic getting encapsulated somewhere it shouldn't be" a completely reasonable leading theory. Every individual data point was real and reproducible — this wasn't a case of chasing noise.
Unlock this article to keep reading, or subscribe for unlimited access to everything. See Pricing for details.