Thanks, I wasn't sure whether kernel or nginx replies to the SYN packets. Now the question is how can I check for the network problems. SYN_RECV is also when kernel has replied with SYN+ACK, but I waiting for a final ACK? But SYN_RECV is also when user-space is unable to accept() the new connections so fast. How can I distinguish between these 2 reasons?
But anyway, why should that prevent legitimate normal connections from being accepted? When I try to access nginx' server-status, I am waiting for many seconds...