By killing SSH and Management access on WAN, we managed to end the brute force attempts into our colo core firewall. Avoiding this kind of configuration seems obvious, but it hadn't really come to light until now. I'm very happy to have this resolved though :D