That sucks. Have you tried UDP over port 53? Also, I find ocserv/opeconnect much better for passing firewalls as it much more closely resembles HTTPS, I find OpenVPN is too easy to fingerprint. It opportunistically uses UDP if it can, otherwise it uses TCP.

You could tunnel with stunnel, which I think would make it quite difficult to fingerprint and distinguish from an ordinary TLS connection.

