So recently on my travels I was a litle frustated by the locale's strict policy on some standard apps. I've got a nginx reverse proxy sitting in my DMZ which I use for anything I need to be accessed ...
ECH encrypts the TLS handshake, backends speak HTTP/2, and Multipath TCP uses multiple network paths in parallel.