OK i can sum this up to what would work best
1: An option in the forum settings to turn this feature on AS WELL a field beside that where the admin can set the length (in minutes), as well as the amount of attempts allowed.
2: A log in the admin panel that lists all account failed login accounts (listing the accounts display name, username, as well as the Ip address of the person trying to login.)
3: Banning the IP of the person attempting to login, for the set amount of time, when the login failed the set about of tries, as well as a Proxy Check.
4. A PM notification send to the user's whos account was being attacked, notifying them of the attack and suggesting them to change their password.
My opinion I think that covers everything. It provide the most user friend and editable options, allowing it to be flexible so that if the user doesn't want to use the feature they dont have to and they can set the values of everything. Also provides notification to both allowed staff as well as the user. It also bans the person's ip instead of the account, preventing the wrong person from being locked out. Adding to that the Proxy Check will make sure that the user is not using a Proxy to change his IP address in order to bypass the IP Ban.