Thanks for your input. I will do the following:
- check the power situation, and make sure the network equipment is all on a suitable UPS.
- run PP on all three Citrix servers.
- tweak MTU and fragmented packet settings on the firewall, and for each VPN tunnel.
- take a closer look at VPN renegotiating.

Sorry, I forgot to diagram the network...

PC (on LAN) running PP -->
Cisco 1000BT switch -->
SonicWALL Pro 200 (.162) -->
Nortel 100BT switch-->
PC (outside firewall) running PP-->
[.161] AT&T 17xx managed router (at my sitein my building) (.126) -->
[.125] AT&T remote access router (at SBC's site) -->
to North Carolina

BTW, the problem existed before I put the Nortel switch outside my firewall, so I can eliminate that as a culprit.

Will post back if/when I find the problem.