If you go to Manage & Settings -> Blades -> Threat Prevention, which fail mode is selected? Fail-open or fail-close? I'm wondering if you are seeing that message because connections are being dropped as the Gateway appears to be under heavy load.
Did you upgrade the 5600's to R80.10, as well, or did you just do the Management?
When was the last time you update your IPS signatures? Is it possible that one or more "High" or "Critical" Performance Impact signatures were set enabled in either Prevent or Detect mode?
R80 CCSA / CCSE