> I think Ural means the initial handshake when connecting to the entry node
> is easily detectable and identifiable by a L7 firewall (which it is).

Initial handshake is L3 detectable too, and easier on L3 than on L7.
Guard node and directory servers IPs and ports are public.

For example, no need of DPI if you see traffic from not Tor node IP to This is a Tor client connecting to one of my guards, here 
Or connection from not Tor node IP to, this is a client 
looking for consensus data from moria1, one of the Tor directory authorities.

Adding STUNNEL encapsulation or obfuscation here change nothing.

