i will surely look into this plus i am beginner on most of the network stuff on here will you be ok if i direct message if need helpChiming in here for a different direction - If DPI is blocking you, read up on bypassing China's GFW. I have setup and used Shadowsocks (with v2ray-plugin over nginx reverse proxy websocket and CDN), vmess, vless, and now my favorite, trojan-go. All of these solutions will allow for running a secure proxy on TCP 443 with proper https TLS handshakes, thus sneaking right by any deep packet inspection while in plain sight.
Trojan-go is a beast to run on Merlin routers though (but can be done on higher end models).. A lighter-weight version of "trojan" is available directly on entware (opkg install trojan) and can be setup in minutes (client or server - server just needs some TLS certs). This version (opposed to trojan-go) is the same protocol but lacks websocket, mux, and a couple other bells and whistles. It works great with proper TCP/UDP forwarding, and might be good enough to get past your super-anal-free-wifi situation without the websocket. (And yes, there are clients for this on iPhone/Android too.)