Thanks for testing in front of the firewall to verify the circuit. So we do know that there is a bandwidth restriction on the SSG.
I would look for any policy that has policer turned on. From the CLI use this command to see if the policer is active. If any lines return on this then you have a policy you need to remove the policer on.
Keyword is pbw (policer bandwidth
get config | inc pbw set policy id 45 from "guest" to "Untrust" "Any-IPv4" "Any-IPv4" "ANY" nat src permit log traffic pbw 500