Port 4434 instead of 443

That will be a problem, I’m afraid. An ACME client talks to the Let’s Encrypt API using HTTPS. The validation requests come from totally different IPs. Your firewall will block it.

You need to unblock port 80, or use DNS validation.