We are seeing sporadic connection issues where tcp syn packets are dropped before reaching our elb. Have noticed off and on for a few weeks now. Still investigating and have support ticket out with aws.
Some more details below, but if you use normalish (naive?) rules in the aws firewall, you get connection tracking behavior and there's an unspecified connection limit for each instance type. Above that limit, incoming syns are dropped.
https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-secu...