- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Generating ACME SSL cert always fails with "Timeout during connect (likely firewall problem)"
Hi there,
I'm trying to generate an ACME cert on my FortiGate, just as I've done on my EMS server, but it always fails with a "Timeout during connect (likely firewall problem)" error:
Port 80 is wide open to the world and you can see the traffic coming in when running a diag sniffer. From me running a curl against http://vpn.<mydomain>.com:
I'm at a loss. Does anyone have any ideas or suggestions?
Thanks!
Solved! Go to Solution.
- Labels:
-
FortiGate
-
FortiGate-VM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
Check here how the challenge is done.
Maybe the ACME server is not able to perform the challenge, probably because your 443 port is closed (TLS-ALPN-01 on 443 is the default for challenge).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If anyone has the same issue later, I've got my HTTPS port set to something other than 443 which enabled me to set the HTTP port to 443 which then was able to communicate with Let's Encrypt. I have "Redirect to HTTPS" enabled to the actual HTTPS port which is blocked from public access.
I think the way the EMS server has this implemented is the right way but at least this config seems to work.
Thanks again!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
Check here how the challenge is done.
Maybe the ACME server is not able to perform the challenge, probably because your 443 port is closed (TLS-ALPN-01 on 443 is the default for challenge).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If anyone has the same issue later, I've got my HTTPS port set to something other than 443 which enabled me to set the HTTP port to 443 which then was able to communicate with Let's Encrypt. I have "Redirect to HTTPS" enabled to the actual HTTPS port which is blocked from public access.
I think the way the EMS server has this implemented is the right way but at least this config seems to work.
Thanks again!
