I'm investigating exactly that. The big question then is "why do we have some sites where all protocols work except a specific few?"

I suppose it's possible that, for example, RDP (and not just to 3389, but all RDP!) is being sent to a DPI system and that hitting the 512K limit has screwed up routing for that protocol. I'll buy that as a possibility, but doing DPI on RDP sessions is really, really rude. I wonder if this didn't have some sort of cascade effect on DPI systems beyond just the basic routing issue.

