# Fetching {domain}/.well-known/acme-challenge/{token} Timeout during connect (likely firewall problem)

**URL:** <https://community.letsencrypt.org/t/fetching-domain-well-known-acme-challenge-token-timeout-during-connect-likely-firewall-problem/245368>\
**Category:** Help\
**Created:** [February 17, 2026, 12:30am UTC](https://community.letsencrypt.org/t/fetching-domain-well-known-acme-challenge-token-timeout-during-connect-likely-firewall-problem/245368 "2026-02-17T00:30:44Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![robertvandeneynde](https://avatars.discourse-cdn.com/v4/letter/r/c2a13f/32.png) [@robertvandeneynde](https://community.letsencrypt.org/u/robertvandeneynde)\
**Post date:** [February 17, 2026, 12:30am UTC](https://community.letsencrypt.org/t/fetching-domain-well-known-acme-challenge-token-timeout-during-connect-likely-firewall-problem/245368/1 "2026-02-17T00:30:44Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [crt.sh | example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

- My domain is: [robertvandeneynde.ru](http://robertvandeneynde.ru)
- I ran this command: `certbot --nginx`
- It produced this output:

```nohighlight
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
  Identifier: robertvandeneynde.ru
  Type: connection
  Detail: {ip}: Fetching http://robertvandeneynde.ru/.well-known/acme-challenge/{token}: Timeout during connect (likely firewall problem)

```

- My web server is (include version): nginx/1.24.0
- The operating system my web server runs on is (include version): Ubuntu 24.04.4 LTS
- I can login to a root shell on my machine (yes or no, or I don't know): yes
- The version of my client is: certbot 5.3.1

My tests:

- The IP in the output is correct (DNS A record propagated).
- I manually create a directory /var/www/html/.well-known
- I manually created a directory /var/www/html/.well-known/acme-challenge
- When I create a file in acme-challenge, I can read it from my browser
- This file is readable from both an IP in russia, and using the VPN to be out of it
- The firewall is disabled (otherwise I would not be able to read the file)
- I searched online and duck duck AI for more than 1h, this is my last resort

Thanks in advance

---

<div class="post-metadata">

**Author:** ![robertvandeneynde](https://avatars.discourse-cdn.com/v4/letter/r/c2a13f/32.png) [@robertvandeneynde](https://community.letsencrypt.org/u/robertvandeneynde)\
**Post date:** [February 17, 2026, 12:33am UTC](https://community.letsencrypt.org/t/fetching-domain-well-known-acme-challenge-token-timeout-during-connect-likely-firewall-problem/245368/2 "2026-02-17T00:33:28Z")

</div>

Edit: I ran certbot in sudo  
Edit: The output says "nginx" instead of "webroot" (but wasn't working with webroot or standalone too).

---

<div class="post-metadata">

**Author:** ![danb35](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/danb35/32/70869_2.png) [@danb35](https://community.letsencrypt.org/u/danb35)\
**Post date:** [February 17, 2026, 1:02am UTC](https://community.letsencrypt.org/t/fetching-domain-well-known-acme-challenge-token-timeout-during-connect-likely-firewall-problem/245368/3 "2026-02-17T01:02:10Z")

</div>

> [@robertvandeneynde](#):
>
> `Timeout during connect (likely firewall problem)`

Isn't this error message pretty clear? Testing shows your site isn't reachable from many places around the world:

> **[Free Website Reachability Check | Semonto](https://semonto.com/tools/website-reachability-check?test=2d3507c2-72c6-46e7-a792-780fca44dcfc)**
>
> Is your website down or available? Do a quick test from multiple locations worldwide with our free reachability checker. Just enter your URL and get instant results.

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [February 17, 2026, 1:12am UTC](https://community.letsencrypt.org/t/fetching-domain-well-known-acme-challenge-token-timeout-during-connect-likely-firewall-problem/245368/4 "2026-02-17T01:12:30Z")

</div>

> [@danb35](#):
>
> Testing shows your site isn't reachable from many places around the world:

Maybe so but it is reachable per other tests. The Let's Debug server reaches it from its own location although the LE Staging test fails with timeout: [Let's Debug](https://letsdebug.net/robertvandeneynde.ru/2724952?debug=y)

I can reach it from my own AWS servers. And, this test site which we use often reaches it from everywhere: [Check website performance and response : Check host - online website monitoring](https://check-host.net/check-report/39a9864ek40f)

That said, it does look like some kind of comms problem possibly affecting just the Primary LE center which uses a Cloudflare product for outbound comms. Or, a selective firewall affecting the Primary LE IP. If it is a comms problem it is far more likely to be nearer their location than near the LE center.

I checked but it does _not_ look like a Palo Alto firewall problem

---

<div class="post-metadata">

**Author:** ![robertvandeneynde](https://avatars.discourse-cdn.com/v4/letter/r/c2a13f/32.png) [@robertvandeneynde](https://community.letsencrypt.org/u/robertvandeneynde)\
**Post date:** [February 17, 2026, 8:30am UTC](https://community.letsencrypt.org/t/fetching-domain-well-known-acme-challenge-token-timeout-during-connect-likely-firewall-problem/245368/5 "2026-02-17T08:30:47Z")

</div>

Thanks, apparently yes, it isn't available from LE servers, but available from a lot of other places (like your AWS Server, my location, my location in VPN).

I thought about doing DNS-01 challenge, but then I used another technique:

- Generate the pem on my Other server (US based) and then copy the files to my .ru server

But I will probably not be able to do the automatic renewal, we'll see in 3 months.

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [February 17, 2026, 2:56pm UTC](https://community.letsencrypt.org/t/fetching-domain-well-known-acme-challenge-token-timeout-during-connect-likely-firewall-problem/245368/6 "2026-02-17T14:56:24Z")

</div>

> [@robertvandeneynde](#):
>
> I thought about doing DNS-01 challenge

Sometimes "backbone" network problems get fixed as those providers resolve the problem on their own. Maybe try again in a few days.

If it persists the DNS Challenge is an option. You could write your own --manual-auth-hook for Certbot. Or, use a different ACME Client that supports [reg.ru](http://reg.ru) directly like lego: [reg.ru :: Let’s Encrypt client and ACME library written in Go.](https://go-acme.github.io/lego/dns/regru/)

---

<div class="post-metadata">

**Author:** ![rinatvaleev](https://avatars.discourse-cdn.com/v4/letter/r/f07891/32.png) [@rinatvaleev](https://community.letsencrypt.org/u/rinatvaleev)\
**Post date:** [February 26, 2026, 11:37am UTC](https://community.letsencrypt.org/t/fetching-domain-well-known-acme-challenge-token-timeout-during-connect-likely-firewall-problem/245368/7 "2026-02-26T11:37:14Z")

</div>

I recommend configuring ipv6 if your hosting provider allows it. This solved the problem for me.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [March 28, 2026, 11:37am UTC](https://community.letsencrypt.org/t/fetching-domain-well-known-acme-challenge-token-timeout-during-connect-likely-firewall-problem/245368/8 "2026-03-28T11:37:21Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
