On another note, I recently set up a Tor bridge with pluggable transports to help those in choked areas. It was a fun homelab challenge, and a good way to spread my privilege of having a free connection.
On another note, I recently set up a Tor bridge with pluggable transports to help those in choked areas. It was a fun homelab challenge, and a good way to spread my privilege of having a free connection.
Sounds like security theater. Using port knocking isn't going to hide the fact there's a SSH connection between you and some server. If anything, having a non standard configuration (non standard port number or port knocking) makes you more suspicious.
Unless you were to attract the attention of somebody in government, and they forced an ISP to escalate an issue to the 3rd or 4th tier of network engineering running the core of the bigger ASes there, they're not going to be doing that. It's not the chinese GFW.
So unless somebody cares to inspect your traffic flow in particular and notices that it's openvpn traffic on 443 and not normal TLS1.2 traffic, it's likely to work.
Firefox has build-in DNS over HTTPS. That will help.