TC based ingress/egress flow tagging, go for userspace and prometheus exporter handling i’m running this on a couple 1 core 1 g ram VPS box with 1 bgp session and a couple more powerful ones can achieve 80% what those big libpcap based solutions with a lot less resource use config example