Can infrastructure providers start dedicating their knowledge of scraper infra to the public domain so we all can start to respond appropriately to these toxic networks?

Pomal
I gave the example of PPPoE, the other option is to read the linked kernel docs to understand traffic steering and infer where those situations could occur.
Opensense is often bound by single-core operations depending on where a network packet may plumb itself through the kernel. A great example is any PPPoE connections on the base OS BSD. Vyos doesn’t have these same limitations since it’s minted on Linux - which supports traffic steering.
Really though, IaC for vyos has always been rock solid. Even though the persistent config in Opnsense is cool, adding new features or configs can be a bit of a pain in the ass