Code:
[admin@WL500GP root]$ tcpdump -vv -i ppp0 -n | grep 10.196.0.18 | grep -v 10.196.0.18.22 | grep -v 10.196.0.18.80
tcpdump: listening on ppp0, link-type LINUX_SLL (Linux cooked), capture size 68 bytes
03:15:40.544045 IP (tos 0x0, ttl 62, id 32765, offset 0, flags [DF], length: 60) 10.196.0.18.52048 > 10.128.62.212.22: S 720249077:720249077(0) win 5840 <mss 1460,sackOK,timestamp 333602568[|tcp]>
03:15:40.547564 IP (tos 0x0, ttl 63, id 0, offset 0, flags [DF], length: 60) 10.128.62.212.22 > 10.196.0.18.52048: S 1031220004:1031220004(0) ack 720249078 win 5792 <mss 1460,sackOK,timestamp 455764208[|tcp]>
03:15:40.577935 IP (tos 0x0, ttl 62, id 32766, offset 0, flags [DF], length: 52) 10.196.0.18.52048 > 10.128.62.212.22: . [tcp sum ok] 1:1(0) ack 1 win 46 <nop,nop,timestamp 333602576 455764208>
03:15:40.583491 IP (tos 0x0, ttl 63, id 17373, offset 0, flags [DF], length: 84) 10.128.62.212.22 > 10.196.0.18.52048: P 1:33(32) ack 1 win 46 <nop,nop,timestamp 455764218 333602576>
03:15:40.610336 IP (tos 0x0, ttl 62, id 32767, offset 0, flags [DF], length: 52) 10.196.0.18.52048 > 10.128.62.212.22: . [tcp sum ok] 1:1(0) ack 33 win 46 <nop,nop,timestamp 333602584 455764218>
03:15:40.611346 IP (tos 0x0, ttl 62, id 32768, offset 0, flags [DF], length: 84) 10.196.0.18.52048 > 10.128.62.212.22: P 1:33(32) ack 33 win 46 <nop,nop,timestamp 333602584 455764218>
03:15:40.613861 IP (tos 0x0, ttl 63, id 17374, offset 0, flags [DF], length: 52) 10.128.62.212.22 > 10.196.0.18.52048: . [tcp sum ok] 33:33(0) ack 33 win 46 <nop,nop,timestamp 455764225 333602584>
03:15:40.614477 IP (tos 0x0, ttl 63, id 17375, offset 0, flags [DF], length: 836) 10.128.62.212.22 > 10.196.0.18.52048: P 33:817(784) ack 33 win 46 <nop,nop,timestamp 455764225 333602584>
03:15:40.661425 IP (tos 0x0, ttl 62, id 32769, offset 0, flags [DF], length: 844) 10.196.0.18.52048 > 10.128.62.212.22: P 33:825(792) ack 33 win 46 <nop,nop,timestamp 333602597 455764225>
03:15:40.699288 IP (tos 0x0, ttl 63, id 17376, offset 0, flags [DF], length: 52) 10.128.62.212.22 > 10.196.0.18.52048: . [tcp sum ok] 817:817(0) ack 825 win 58 <nop,nop,timestamp 455764247 333602597>
03:15:40.711726 IP (tos 0x0, ttl 62, id 32770, offset 0, flags [DF], length: 52) 10.196.0.18.52048 > 10.128.62.212.22: . [tcp sum ok] 825:825(0) ack 817 win 58 <nop,nop,timestamp 333602610 455764225>
03:15:40.727255 IP (tos 0x0, ttl 62, id 32771, offset 0, flags [DF], length: 76) 10.196.0.18.52048 > 10.128.62.212.22: P 825:849(24) ack 817 win 58 <nop,nop,timestamp 333602614 455764247>
03:15:40.728750 IP (tos 0x0, ttl 63, id 17377, offset 0, flags [DF], length: 52) 10.128.62.212.22 > 10.196.0.18.52048: . [tcp sum ok] 817:817(0) ack 849 win 58 <nop,nop,timestamp 455764254 333602614>
03:15:40.729248 IP (tos 0x0, ttl 63, id 17378, offset 0, flags [DF], length: 204) 10.128.62.212.22 > 10.196.0.18.52048: P 817:969(152) ack 849 win 58 <nop,nop,timestamp 455764254 333602614>
03:15:40.767308 IP (tos 0x0, ttl 62, id 32772, offset 0, flags [DF], length: 52) 10.196.0.18.52048 > 10.128.62.212.22: . [tcp sum ok] 849:849(0) ack 969 win 71 <nop,nop,timestamp 333602623 455764254>
03:15:40.767312 IP (tos 0x0, ttl 62, id 32773, offset 0, flags [DF], length: 196) 10.196.0.18.52048 > 10.128.62.212.22: P 849:993(144) ack 969 win 71 <nop,nop,timestamp 333602624 455764254>
03:15:40.773865 IP (tos 0x0, ttl 63, id 17379, offset 0, flags [DF], length: 772) 10.128.62.212.22 > 10.196.0.18.52048: P 969:1689(720) ack 993 win 70 <nop,nop,timestamp 455764265 333602624>
03:15:40.812494 IP (tos 0x0, ttl 62, id 32774, offset 0, flags [DF], length: 68) 10.196.0.18.52048 > 10.128.62.212.22: P 993:1009(16) ack 1689 win 83 <nop,nop,timestamp 333602635 455764265>
03:15:40.851735 IP (tos 0x0, ttl 63, id 17380, offset 0, flags [DF], length: 52) 10.128.62.212.22 > 10.196.0.18.52048: . [tcp sum ok] 1689:1689(0) ack 1009 win 70 <nop,nop,timestamp 455764285 333602635>
03:15:40.877695 IP (tos 0x0, ttl 62, id 32775, offset 0, flags [DF], length: 100) 10.196.0.18.52048 > 10.128.62.212.22: P 1009:1057(48) ack 1689 win 83 <nop,nop,timestamp 333602651 455764285>
03:15:40.878863 IP (tos 0x0, ttl 63, id 17381, offset 0, flags [DF], length: 52) 10.128.62.212.22 > 10.196.0.18.52048: . [tcp sum ok] 1689:1689(0) ack 1057 win 70 <nop,nop,timestamp 455764291 333602651>
03:15:40.879017 IP (tos 0x0, ttl 63, id 17382, offset 0, flags [DF], length: 100) 10.128.62.212.22 > 10.196.0.18.52048: P 1689:1737(48) ack 1057 win 70 <nop,nop,timestamp 455764291 333602651>
03:15:40.907359 IP (tos 0x0, ttl 62, id 32776, offset 0, flags [DF], length: 116) 10.196.0.18.52048 > 10.128.62.212.22: P 1057:1121(64) ack 1737 win 83 <nop,nop,timestamp 333602658 455764291>
03:15:40.910112 IP (tos 0x0, ttl 63, id 17383, offset 0, flags [DF], length: 116) 10.128.62.212.22 > 10.196.0.18.52048: P 1737:1801(64) ack 1121 win 70 <nop,nop,timestamp 455764299 333602658>
03:15:40.991101 IP (tos 0x0, ttl 62, id 32777, offset 0, flags [DF], length: 52) 10.196.0.18.52048 > 10.128.62.212.22: . [tcp sum ok] 1121:1121(0) ack 1801 win 83 <nop,nop,timestamp 333602680 455764299>
03:15:44.591417 IP (tos 0x0, ttl 62, id 32778, offset 0, flags [DF], length: 196) 10.196.0.18.52048 > 10.128.62.212.22: P 1121:1265(144) ack 1801 win 83 <nop,nop,timestamp 333603580 455764299>
03:15:44.592577 IP (tos 0x0, ttl 63, id 17384, offset 0, flags [DF], length: 84) 10.128.62.212.22 > 10.196.0.18.52048: P 1801:1833(32) ack 1265 win 83 <nop,nop,timestamp 455765220 333603580>
03:15:44.620656 IP (tos 0x0, ttl 62, id 32779, offset 0, flags [DF], length: 52) 10.196.0.18.52048 > 10.128.62.212.22: . [tcp sum ok] 1265:1265(0) ack 1833 win 83 <nop,nop,timestamp 333603587 455765220>
03:15:44.620660 IP (tos 0x0, ttl 62, id 32780, offset 0, flags [DF], length: 180) 10.196.0.18.52048 > 10.128.62.212.22: P 1265:1393(128) ack 1833 win 83 <nop,nop,timestamp 333603587 455765220>
03:15:44.623969 IP (tos 0x0, ttl 63, id 17385, offset 0, flags [DF], length: 100) 10.128.62.212.22 > 10.196.0.18.52048: P 1833:1881(48) ack 1393 win 95 <nop,nop,timestamp 455765228 333603587>
03:15:44.657844 IP (tos 0x8, ttl 62, id 32781, offset 0, flags [DF], length: 180) 10.196.0.18.52048 > 10.128.62.212.22: P 1393:1521(128) ack 1881 win 83 <nop,nop,timestamp 333603596 455765228>
03:15:44.665402 IP (tos 0x8, ttl 63, id 17386, offset 0, flags [DF], length: 132) 10.128.62.212.22 > 10.196.0.18.52048: P 1881:1961(80) ack 1521 win 108 <nop,nop,timestamp 455765238 333603596>
03:15:44.665563 IP (tos 0x8, ttl 63, id 17387, offset 0, flags [DF], length: 100) 10.128.62.212.22 > 10.196.0.18.52048: P 1961:2009(48) ack 1521 win 108 <nop,nop,timestamp 455765238 333603596>
03:15:44.709339 IP (tos 0x8, ttl 62, id 32782, offset 0, flags [DF], length: 52) 10.196.0.18.52048 > 10.128.62.212.22: . [tcp sum ok] 1521:1521(0) ack 2009 win 83 <nop,nop,timestamp 333603609 455765238>
03:15:44.710345 IP (tos 0x8, ttl 62, id 32783, offset 0, flags [DF], length: 132) 10.196.0.18.52048 > 10.128.62.212.22: P 1521:1601(80) ack 2009 win 83 <nop,nop,timestamp 333603609 455765238>
03:15:44.712292 IP (tos 0x8, ttl 63, id 17388, offset 0, flags [DF], length: 196) 10.128.62.212.22 > 10.196.0.18.52048: P 2009:2153(144) ack 1601 win 108 <nop,nop,timestamp 455765250 333603609>
03:15:45.009207 IP (tos 0x8, ttl 63, id 17389, offset 0, flags [DF], length: 196) 10.128.62.212.22 > 10.196.0.18.52048: P 2009:2153(144) ack 1601 win 108 <nop,nop,timestamp 455765325 333603609>
Вот примерно так, как видно размеры пакетов много меньше 1500 и зависает всё в момент начала передачи самого файла, то есть когда собираются идти большие пакеты.