Following problem:
With firewall we get invalid Port in redirect target. Without Firewall we can connect to /.well-known/acme-challange/test. The certbot-auto certonly command was running without the fierewall.
• http://itnn-db-test.de/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
178.254.33.168
302
https://itnn-db-test.de:8443/.well-known/acme-challenge/check-your-website-dot-server-daten-dot-de
0.063
A
Letsencrypt doesn't follow redirects to non-standard-ports. So that can't work. Remove that redirect, minimal, if the subdirectory starts with /.well-known/acme-challenge.
But curious: That error isn't visible, there is a http status 404 - Not Found visible.