To save the read, the symptoms were packet loss between the firewall and the router and huge lots of concurrent connections with 4+ day timeouts not dropping.
Basically I implemented QoS on SMTP reserving 512K for all other traffic turning my 2Mb/2Mb link into a 2Mb/512K link (for web browsers) which is working pretty well.
What happens is once a day a daily email is sent out to around 40K subscribers via IIS5's SMTP server on Win2k.
All the 4+day timeout connection traffic is from the SMTP server through the firewall to the various SMTP servers its connecting to sending the emails.
After the mail run, I go onto the mail server and do netstat commands to see the current connections its not showing any connections, I can even reboot the server and disable the SMTP server so I am SURE there are no connections from that machine out through the firewall (or pull the network cable) makes no difference, Astaro still has the connections showing.
The first time the mail goes out the Concurrent connections jumps from a normal 2-300 up to 2K+ and stays there till the next mail goes out, then it jumpst to 4K+ and I imagine if I keep it up it will jump 2K each time till some of the old connections eventually timeout after 4 or 5 days.
Why is Astaro keeping these connections alive even though the initiating machine isn't?
Has this issue been addressed in v5 of ASL, I can try upgrading and see if it fixes it however I'd prefer not to.
Or is it a IIS SMTP bug?
Any insight would be appreciated or I should I call support?

This thread was automatically locked due to age.