You don't show what the interface setups are on the switch, PIX
and old 1721. Duplex or MTU may play a role here.
What about route entries(is the PIX aimed at the same gateway(s) as
the 1721 was?)
How many clients do you have? Is there a router/L3 switch between the
clients and the PIX? If so, then I don't believe the NB would be an issue,
unless it's all going over a GRE tunnel.
A quick look through the rules listed, you don't lock down much. Possibly
someone has learned they can use just about any other protocol to bypass
your proxy. By any chance is utilitzation of the circuit higher?