I started out thinking that NordVPN are misrepresenting themselves in their marketing bumph
"To guarantee the protection of your sensitive data, NordVPN uses AES-256-GCM encryption algorithm with a 4096-bit DH key."
I've just randomly selected a range of UDP .ovpn config files from the 'set up your own' area of my account and they all feature
But then I found this page: https://community.openvpn.net/openvpn/wiki/DeprecatedOptions which seems to suggest that the --data-ciphers tag is part of the server deployment (which seems to fit my notion that it's not just a config file issue) the section called 'Policy: Migrate away from deprecated ciphers. Status: In progress' it says:
If both client and server runs OpenVPN v2.4, the tunnel will automatically be upgraded to AES-256-GCM. If the environment also uses clients older than OpenVPN v2.4, the server can deploy:
Which seems to suggest that if --data-ciphers is set to include 'CBC' at deployment then it'll accept a CBC definition and switch ('upgrade') it to GCM? (maybe NordVPN are telling the truth?)