You can always run an ssh bastion server on port 443. It's indistinguishable from https traffic without deep packet inspection or great-firewall-of-china like pattern analysis.
Just have a bastion host with that and you'll have no trouble ssh -A'ing your way there and then on to the real box on whatever port it's on.