I'm planing to build a device (prototype) that act as a portable security gateway. To make this, I choosed OpenWRT running on Raspberry Pi with OpenVPN for VPN connection. My main purpose of this build is develop a unit (prototype), that single individual can use with easy configurations which protect him from DPI solutions.
As we know, there are many sophisticated network security appliances (NGFWs), that have state of the art DPI capabilities. As per the my knowledge, securing SSL traffic from this kind of devices are impossible.
My question is: Can OpenVPN alone protect user from the kind of interception (and SSL decryption) or do they need further layers of protection?