How, technically, can they block wire guard? It can operate as pure UDP on any port. Are we referring to wireguard vendors like tailscale here?
also HN discussions of it[2]:
https://lists.zx2c4.com/pipermail/wireguard/2016-July/000184...
... is pretty informative. There is a PSK mode, which really should be essentially indistinguishable from random UDP packets. But I haven't read deeply enough. I do PSK on all my networks, but that has its own disadvantages. I honestly thought that was the only way to do wireguard.
Why analyze when you can whitelist?
In which case what we need is https side channel VPNs.
maybe not