Timeout during connect (likely firewall problem) - not my server's issue

Without the actual domain names we cannot give specific advice. You also did not answer many of the other questions on the form you should have been shown posting in the Help topic.

So, some general comments

A successful challenge should show at minimum 4 and probably 5 "200" replies from your server. If you see less that means something is blocking some Let's Encrypt servers.

Recently LE introduced new non-USA based server validation points. You should check whether you block by geography. If so, either un-block that or allow any /.well-known/acme-challenge/ URI from anywhere. Or, consider switching to the DNS Challenge if your auth DNS servers are not geo-blocked.

The answers to the other questions would have probably allowed us to pinpoint exactly what is happening.