Can I ask you what your network hardware is and how customized your kernel is (i.e., are you patching the network stack at all or running some vendor-customized drivers, or is it all in mainline)?
We use fairly standard Mellanox and Chelsio 100GbE NICs. Except for TLS sendfile and our vectorized mbufs, most of the patches that we've been running have actually been to the VM system. Thankfully, due in large part to the recent efforts to scale the VM system upstream, a lot of our hacks are going away.