In short, the new router we have in place still isn't sufficient to handle the new filtering - we are currently making arrangements to replace it completely with a Brocade build that can easily tank the stress. The issue stems from the filtering in Las Vegas - we recently replaced CNServers (who blocked all UDP) with Staminus (who mitigates but allows UDP), and it turns out that the sheer volume of incoming UDP is sufficient to spike the router's CPU high enough that it simply locks up.
As a temporary fix, we've manually blocked all UDP on our Vegas filtering. This should put things back to normal until we can get the Brocade in place.