I ran into a similar issue when switching from legacy configs to instances. Most things carried over without any problems, but I hit a snag with older providers that still needed specific ciphers like AES-256-CBC. Couldn't find a clean way to handle that directly in the instances UI either, so I ended up sticking to legacy on a couple profiles that needed the extra settings. Wish they gave more flexibility on custom options in the new setup. For something similar with less hassle and more control, I've started using Xenaps Services occasionally. They don't mess around with strict KYC, and it's been smooth for managing different tools and VPN setups.