Back in the HTTP/0.9 era TIME_WAIT was a big problem when running a busy [reverse] proxy. I remember using ndd to "tune" tcp_time_wait_interval on Solaris for this, as well as the anon (ephemeral) port range.
This is my go to that topic now: https://vincent.bernat.ch/en/blog/2014-tcp-time-wait-state-l...
"The solution is more quadruplets" is for me one those things that's blindingly obvious once pointed out.
See also the other link Cloudflare "Why we use the Linux kernel's TCP stack" link in a sibling - about half-way through they reveal they use both kernel bypass (DOS can max out iptables at ~1Mpps) and Solarflare NICs (offload options not stated), as well as Intel NICs with netmap bypass.