Now it is sure that firewall is not blocking traffic.. I used tcpdump to eth1 and it says this when something start to block traffic:
18:24:03.131958 80.223.XXX.XXX.3703 > 80.223.1XX.XXX.135: S 3837510325:3837510325
(0) win 16384 <mss 1460,nop,nop,sackOK> (DF)
18:24:06.059505 80.223.XX.XXX.3703 > 80.223.1XX.XXX.135: S 3837510325:3837510325
(0) win 16384 <mss 1460,nop,nop,sackOK> (DF)
18:24:12.068381 80.223.XXX.XXX.3703 > 80.223.1XX.XXX.135: S 3837510325:3837510325
(0) win 16384 <mss 1460,nop,nop,sackOK> (DF)
18:24:28.584656 62.73.33.48.6667 > 80.223.1XX.XXX.33272: FP 0:108(108) ack 1 win
2896 <nop,nop,timestamp 539259193 2156662> (DF)
18:24:37.867088 80.223.1XX.XXX > 80.223.1XX.XXX: icmp: echo request
18:25:24.138067 80.223.1XX.XXX.4014 > 80.223.1XX.XXX.445: S 3881765756:388176575
6(0) win 64240 <mss 1460,nop,nop,sackOK> (DF)
18:25:27.095391 80.223.1XX.XXX.4014 > 80.223.1XX.XXX.445: S 3881765756:388176575
6(0) win 64240 <mss 1460,nop,nop,sackOK> (DF)
18:25:29.034455 81.35.129.147.3318 > 80.223.1XX.XXX.135: S 2524344233:2524344233
(0) win 16384 <mss 1452,nop,nop,sackOK> (DF)
18:25:32.584186 62.73.33.48.6667 > 80.223.1XX.XXX.33272: FP 0:108(108) ack 1 win
2896 <nop,nop,timestamp 539265593 2156662> (DF)
18:25:32.816215 81.35.129.147.3318 > 80.223.1XX.XXX.135: S 2524344233:2524344233
(0) win 16384 <mss 1452,nop,nop,sackOK> (DF)
Does this say anything to someone?

Edit: Those don't come when is traffic on eth1