Hello Martin,
A packet-Capture will be needed to determine the real cause of the problem.
What we are talking here about is the TCP normalizer which makes the FW such a great Firewall option on the market because of all the things it does.
You could try the TCP state bypass feature on the FW for the traffic suffering to see if it does make a difference (It should, less checks for the normalization)
Looking for some Networking Assistance?
Contact me directly at jcarvaja@laguiadelnetworking.com
I will fix your problem ASAP.
Cheers,
Julio Carvajal Segura
http://laguiadelnetworking.com
Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC