Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
* About to connect() to acme-v02.api.letsencrypt.org port 80 (#0)
* Trying 208.91.112.55...
* Connected to acme-v02.api.letsencrypt.org (208.91.112.55) port 80 (#0)
> GET / HTTP/1.1
> User-Agent: curl/7.29.0
> Host: acme-v02.api.letsencrypt.org
> Accept: */*
>
< HTTP/1.1 403 Forbidden
< Connection: close
< Content-Type: text/html
< Cache-Control: no-cache
< X-Frame-Options: SAMEORIGIN
< X-XSS-Protection: 1; mode=block
< X-Content-Type-Options: nosniff
< Content-Security-Policy: frame-ancestors
< Content-Length: 1561
<
<!-- IE friendly error message walkround.
if error message from server is less than
512 bytes IE v5+ will use its own error
message instead of the one returned by
server. -->
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01//EN">
<html><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8"><style type="text/css">html,body{height:100%;padding:0;margin:0;}.oc{display:table;width:100%;height:100%;}.ic{display:table-cell;vertical-align:middle;height:100%;}div.msg{display:block;border:1px solid #30c;padding:0;width:500px;font-family:helvetica,sans-serif;margin:10px auto;}h1{font-weight:bold;color:#fff;font-size:14px;margin:0;padding:2px;text-align:center;background: #30c;}p{font-size:12px;margin:15px auto;width:75%;font-family:helvetica,sans-serif;text-align:left;}</style><title>Web Application Firewall</title></head><body><div class="oc"><div class="ic"><div class="msg"><h1>Web Application Firewall</h1><p><p>The transfer has triggered a Web Application Firewall.</p>
<p>
This transfer is blocked.
URL: http://acme-v02.api.letsencrypt.org/<br />
<br/>Event ID : 110000003
<br/>Event Type: signature
</p></p></div></div></div></body></html>
* Closing connection 0
The IP address being resolved is 208.91.112.55 which is not a Let’s Encrypt IP. It belongs to the company Fortinet. It appears you may have some sort of internet filter which is blocking your outgoing request.
I'd like to read the verbiage on that "company" policy.
Sounds more like a misconfiguration OR an overzealous firewall admin.
[if NOT a mis-categorization by Fortinet]