OK, Guys, I'm totaly confused now:
take a look for the packet capture I did and for the snoop from juniper. Can be that juniper just dicard packets when it hit some rate?
I do remember we had an issue with ISG 1000 / 2000 when it were able to drop packet without any notification once tcp timer expired (i.e. firewall was thinking that session is expired), while endpoint were trying to 're-establish" connection.