The box was definately not overloaded, it just ran amok killing sessions :)

Wouldn't that be the definition of overloaded? :-)

Please see my answer to Larry with further informations about this incident.
There i also describe why the 2400 does not log ip adresses.

I think it's kind of moot, since the evidence suggests that an IPS is not the right solution for the problem you're trying to solve.

As others have suggested, if you're trying to protect against DDoS attacks, IPS devices are probably not the right approach. DDoS attacks are a special category of attack that take specialized equipment as well as coordination with your upstream vendors to overcome. And frankly, I'm not convinced there really is an answer. Drive enough "legitimate" traffic to a site, any site, no matter how well it's sized and load balanced, and you will DoS the site. DDoS appliances can mitigate but not completely stop that sort of attack, especially from distributed botnets with nodes all over the world.

