Tor's obfs4 protocol is pretty difficult to block, and it has some other transports that are options if obfs4 is unusable in a heavy censorship regime. This page is a good overview of how to start; with the right transport and bridge setup it'll be extremely difficult for your ISP to prevent you having access.
You could make your home server a securely-accessed onion site and connect to a remote-access-via-web service you're running there. That part might be a little challenging (and this process overall may be overkill) but it'd be very challenging for them to block it, I think, so if you've tried some things and had no luck, that might be the way to do it.
Sounds like your government is fairly strict on what you can do. I would suggest Tor but that may be illegal. I would be careful not to do anything that could jeopardize your safety.
Interesting - I had not. It was ages ago I was doing something like what I posted (well before that project ever got started) and it worked "well enough" for what I was doing at the time. Usually I'd run a SOCKS proxy on that second SSH line (-D 4444) and just point my browser at localhost:4444 to route everything home (or use foxyproxy to only route some traffic home).
Looks like sshuttle may have better performance though and provide similar functionality.
If they're blocking Wireguard/OpenVPN at the protocol level, there may not be anything you can do (running on a different port, etc).
If HTTPS works, between a cloud VPS and your home connection, you might be able to setup Nginx + VPN-WS on your cloud host to make a websocket-based VPN.
I haven't tried this, but it looks solid enough. Just make sure you configure Nginx correctly for authentication since it doesn't do that on its own (intentionally since most web servers already have a solid authentication framework / plugin system).
You may also try SSH port forwarding. Basically your home device maintains a persistent connection to the cloud server over SSH and forwards one or more ports (its SSH, for example) over that, and the cloud server makes that available.
Wireguard doesn't obfuscate its traffic so non-standard ports may not help depending on how sophisticated the blocking is (they could recognize the protocol and block your traffic regardless of port).
@mfat@lemdro.id I would try an ssh tunnel... not the best solution (you need to configure it as a SOCKS proxy and specify ports, etc), but worth a try.
Have you tried https://shadowsocks.org/? I don't have any experience with it, but heard it is good at masquerading your traffic and making it almost impossible for your ISP to block it
@mfat Depending on how they’re blocking VPNs (i.e. blocking specific ports, or allowing specific ports), you may be able to run one on a non-standard port. As an extreme example, you could run Wireguard on port 80 (HTTP), which is practically the last possible port that can ever be blocked on public internet.