I've been using Floodgate on Secureplatform for while now and the performance is decent; however, the Floodgate license, AFAIK, is quite expensive. Maybe I am wrong and someone can correct me on this one. IMHO, one of your possible solution is to implement Cisco "rate limiting" or "Network Based Application Recognition (NBAR)" on the upstream Router. Both of the features come with Cisco IOS.