Worth putting a question to the HQ side too, since "never arrives" cuts both ways.
If there is DDoS scrubbing, a transit provider filter, or an upstream ACL sitting in front of that firewall, traffic can be dropped before it ever reaches the interface you're capturing on - and your capture would look exactly like it does now. Ask whoever provides HQ transit whether that source prefix, or the whole consumer ISP range it lives in, is currently being filtered, scrubbed or rate limited.
It's a five minute question, and it's the only theory on this page that explains "nothing in the capture" without involving the client's ISP at all. Rule it out before you send the customer down the road of arguing with their provider.