I have a 2012 R2 Terminal Server used for Remote Desktop connections. We have been experiencing slow connections and cutoffs throughout a given day so I decided to investigate.
When I connect to the server and run, for example, Wireshark to see what is hitting the NIC, I see that in a 10-second capture there are maybe 800 packets coming from my public IP.
No other remote connection shows anywhere near this many packets. This behavior doesn't seem normal.
I have attached a file showing the packet capture from Wireshark. 126.96.36.199 is my public IP.