It's HTTPS traffic so nothing much to see there.

But it looks like the client is starting with RST packet out of the blue. So I guess you need to dig into the debug option on the client site to investigate.

And I recommend you strip the ARP packets from the upload. Saves a lot of not relevant packets.

Why everyone sets DF flags these days. I don't know. But it sure makes it easier to break thing.