Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
You likely have a local network configuration problem.
One possibility is you have incorrect range of private IP addresses that start with 172. Private IP should only be for the range 172.16.0.0/12.
If you setup your local network (wrongly) to use, say, 172.0.0.0/8 that declares a wider range of IP addresses as private. Your local network won't then route requests for these extra IP to the public internet. The acme-v02 IP is between /8 and /12 so you won't be able to reach it.
What does this show? It might help determine if that is the problem
Looks like a routing problem in your local network. Review any private IP ranges in your networking gear and configurations.
Based on your DNS settings it looks like you plan to proxy your domain at Cloudflare. If that is your plan have you considered using one of their Origin CA Certificates? If that works for you then you may not even need a cert from Let's Encrypt. See: Cloudflare origin CA · Cloudflare SSL/TLS docs
So I found that for some reason my internet provider (Comcast/Xfinity) is not allowing replies. Just switching from my provider to my Verizon phone using it as a hotspot allows things to ping and traceroute just fine. Even just pings to letsencrypt.org are timing out. I have reached out to Xfinity support to see if they can do something from their end.