My current understanding is that Wireguard requires "listening port" on the client be opened from outside, but on the corporate WiFi all ports are blocked from outside, so Wireguard cannot work.
Apparently, outgoing port communication is allowed, so OVPN can create a tunnel on port 1194, which...