Earlier quoted context omitted.
The obvious workaround is to uuencode your TLV data and then wrap it in . If it's properly formatted HTML, and the body isn't recognizable as, say, a ZIP file, DPI will pass it. Granted, someone could do entropy detection, and e.g. pass only things that look statistically like valid English/Persian/etc. text. But that needs more compute power, and can be worked around as well using statistical methods similar to Huff…
It'd be awesome to hear from someone with product experience. My experience of DPI is limited to Tenix diodes (which are white-list based, and are more focused around stripping malicious code by converting known objects to another format, eg .jpg to .png and back, or Word to PDF and back), or McAfee's Secure Web (used to be Web Washer), which does URL filtering, SSL scanning, etc. Also white list based.
FWIW our product can do this very quickly (we sell a 1U which can inspect 8 Gb/s).