Oscar,
Packet-tracers from the WAN interface (source interface of the crypto map) will show this drop in that way since the packet-tracer used cannot generate an encrypted packet. Sourcing from the LAN side interface(s) as you did in the other one wi...
If you are using TLS for the AnyConnect data session it would be worth changing this over to DTLS. This tends to help with throughput issues. This document also goes over various points to check for performance issues with the AnyConnect:https://www....