# Timeout during connect (likely firewall problem)

**URL:** <https://community.letsencrypt.org/t/timeout-during-connect-likely-firewall-problem/227642>\
**Category:** Help\
**Created:** [October 21, 2024, 7:55pm UTC](https://community.letsencrypt.org/t/timeout-during-connect-likely-firewall-problem/227642 "2024-10-21T19:55:42Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![danielwi](https://avatars.discourse-cdn.com/v4/letter/d/b38774/32.png) [@danielwi](https://community.letsencrypt.org/u/danielwi)\
**Post date:** [October 21, 2024, 7:55pm UTC](https://community.letsencrypt.org/t/timeout-during-connect-likely-firewall-problem/227642/1 "2024-10-21T19:55:42Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: [lokago.de](http://lokago.de)

I ran this command: certbot -v

It produced this output:

2024-10-21 19:51:39,971:INFO:certbot.\_internal.auth\_handler:Challenge failed for domain [lokago.de](http://lokago.de)  
2024-10-21 19:51:39,971:INFO:certbot.\_internal.auth\_handler:Challenge failed for domain [www.lokago.de](http://www.lokago.de)  
2024-10-21 19:51:39,971:INFO:certbot.\_internal.auth\_handler:http-01 challenge for [lokago.de](http://lokago.de)  
2024-10-21 19:51:39,971:INFO:certbot.\_internal.auth\_handler:http-01 challenge for [www.lokago.de](http://www.lokago.de)  
2024-10-21 19:51:39,971:DEBUG:certbot.\_internal.display.obj:Notifying user:  
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:  
Domain: [lokago.de](http://lokago.de)  
Type: connection  
Detail: 207.154.228.245: Fetching [https://lokago.de/.well-known/acme-challenge/5j95xih\_S-ILzOlVKDrhfq0xiVJ\_G4erDPEIZUiRKj4:](https://lokago.de/.well-known/acme-challenge/5j95xih_S-ILzOlVKDrhfq0xiVJ_G4erDPEIZUiRKj4:) Timeout during connect (likely firewall problem)

Domain: [www.lokago.de](http://www.lokago.de)  
Type: connection  
Detail: 207.154.228.245: Fetching [https://www.lokago.de/.well-known/acme-challenge/j-OljrvHqEQs2bC5Tsl3FXiLfR2MB3EVm4qBN9i6YQs:](https://www.lokago.de/.well-known/acme-challenge/j-OljrvHqEQs2bC5Tsl3FXiLfR2MB3EVm4qBN9i6YQs:) Timeout during connect (likely firewall problem)

Hint: The Certificate Authority failed to download the temporary challenge files created by Certbot. Ensure that the listed domains serve their content from the provided --webroot-path/-w and that files created there can be downloaded from the internet.

2024-10-21 19:51:39,972:DEBUG:certbot.\_internal.error\_handler:Encountered exception:  
Traceback (most recent call last):  
File "/usr/lib/python3/dist-packages/certbot/\_internal/auth\_handler.py", line 108, in handle\_authorizations  
self.\_poll\_authorizations(authzrs, max\_retries, max\_time\_mins, best\_effort)  
File "/usr/lib/python3/dist-packages/certbot/\_internal/auth\_handler.py", line 212, in \_poll\_authorizations  
raise errors.AuthorizationError('Some challenges have failed.')  
certbot.errors.AuthorizationError: Some challenges have failed.

My web server is (include version): nginx version: nginx/1.26.1

The operating system my web server runs on is (include version):  
Linux [shop-beta.lokago.de](http://shop-beta.lokago.de) 6.8.0-47-generic #47-Ubuntu SMP PREEMPT\_DYNAMIC Fri Sep 27 21:40:26 UTC 2024 x86\_64 x86\_64 x86\_64 GNU/Linux

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): yes (spinupwp)

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): certbot 2.9.0

nmap -Pn -p80,443 [lokago.de](http://lokago.de)  
Starting Nmap 7.95 ( [https://nmap.org](https://nmap.org) ) at 2024-10-21 22:46 EEST  
Nmap scan report for [lokago.de](http://lokago.de) (207.154.228.245)  
Host is up (0.071s latency).  
Other addresses for [lokago.de](http://lokago.de) (not scanned): 2a03:b0c0:3:d0::1093:a001  
rDNS record for 207.154.228.245: [shop-beta.lokago.de](http://shop-beta.lokago.de)  
PORT STATE SERVICE  
80/tcp open http  
443/tcp open https  
Nmap done: 1 IP address (1 host up) scanned in 1.01 seconds

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [October 21, 2024, 8:00pm UTC](https://community.letsencrypt.org/t/timeout-during-connect-likely-firewall-problem/227642/2 "2024-10-21T20:00:59Z")

</div>

> [@danielwi](#):
>
> nmap -Pn -p80,443 [lokago.de](http://lokago.de)  
> Starting Nmap 7.95 ( [https://nmap.org](https://nmap.org) ) at 2024-10-21 22:46 EEST  
> Nmap scan report for [lokago.de](http://lokago.de) (207.154.228.245)  
> Host is up (0.071s latency).  
> Other addresses for [lokago.de](http://lokago.de) (not scanned): 2a03:b0c0:3:d0::1093:a001  
> rDNS record for 207.154.228.245: [shop-beta.lokago.de](http://shop-beta.lokago.de)  
> PORT STATE SERVICE  
> 80/tcp open http  
> 443/tcp open https  
> Nmap done: 1 IP address (1 host up) scanned in 1.01 seconds

This is the case for IPv4, however _NOT_ for IPv6:

```nohighlight
$ nmap -Pn -p80,443 -6 lokago.de
Starting Nmap 7.95 ( https://nmap.org ) at 2024-10-21 21:58 CEST
Nmap scan report for lokago.de (2a03:b0c0:3:d0::1093:a001)
Host is up.
Other addresses for lokago.de (not scanned): 207.154.228.245

PORT STATE SERVICE
80/tcp filtered http
443/tcp filtered https

Nmap done: 1 IP address (1 host up) scanned in 19.55 seconds
$ 

```

Let's Encrypt prefers IPv6. It's strange the challenge even got to the `https://` part, as it starts with `http://`. Although I believe the IPv4 fallback behaves a little bit weird in that in the initial phase there's some fallback being done, but after the redirect not any more.

You need to fix your IPv6. Perhaps a firewall.

---

<div class="post-metadata">

**Author:** ![danielwi](https://avatars.discourse-cdn.com/v4/letter/d/b38774/32.png) [@danielwi](https://community.letsencrypt.org/u/danielwi)\
**Post date:** [October 21, 2024, 8:23pm UTC](https://community.letsencrypt.org/t/timeout-during-connect-likely-firewall-problem/227642/3 "2024-10-21T20:23:54Z")

</div>

Thank you for the quick answer. As far as I can tell, the firewall configuration looks good:

ufw status  
Status: active

To Action From

* * *

22 ALLOW Anywhere  
80 ALLOW Anywhere  
443 ALLOW Anywhere  
22 (v6) ALLOW Anywhere (v6)  
80 (v6) ALLOW Anywhere (v6)  
443 (v6) ALLOW Anywhere (v6)

Also I'm not sure why this issue suddenly popped up. It worked fine for the last couple of years...

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [October 21, 2024, 8:28pm UTC](https://community.letsencrypt.org/t/timeout-during-connect-likely-firewall-problem/227642/4 "2024-10-21T20:28:33Z")

</div>

Maybe Digital Ocean changed your IPv6 address or has something interfering?

Does this show the same value as the AAAA record value

```nohighlight
curl -6 https://ifconfig.io

```

I can't reach your home page on IPv6 from my own test server. Not unique to Let's Encrypt

```nohighlight
curl -i6 -m8 http://lokago.de
curl: (28) Connection timed out after 8001 milliseconds

```

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 21, 2024, 8:38pm UTC](https://community.letsencrypt.org/t/timeout-during-connect-likely-firewall-problem/227642/5 "2024-10-21T20:38:17Z")

</div>

> [@MikeMcQ](#):
>
> Maybe Digital Ocean changed your IP...

What show?:  
`curl -4 ifconfig.me`  
`curl -6 ifconfig.me`

[let's check both]

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [October 21, 2024, 8:41pm UTC](https://community.letsencrypt.org/t/timeout-during-connect-likely-firewall-problem/227642/6 "2024-10-21T20:41:18Z")

</div>

> [@rg305](#):
>
> [let's check both]

HTTPS to their IPv4 address gets a cert with their domain name. Probably is right one 🙂

---

<div class="post-metadata">

**Author:** ![danielwi](https://avatars.discourse-cdn.com/v4/letter/d/b38774/32.png) [@danielwi](https://community.letsencrypt.org/u/danielwi)\
**Post date:** [October 21, 2024, 8:41pm UTC](https://community.letsencrypt.org/t/timeout-during-connect-likely-firewall-problem/227642/7 "2024-10-21T20:41:38Z")

</div>

> [@rg305](#):
>
> curl -4 [ifconfig.me](http://ifconfig.me)

curl -4 [ifconfig.me](http://ifconfig.me)  
207.154.228.245

curl -6 [ifconfig.me](http://ifconfig.me)  
2a03:b0c0:3:d0::1b30:4001

---

<div class="post-metadata">

**Author:** ![danielwi](https://avatars.discourse-cdn.com/v4/letter/d/b38774/32.png) [@danielwi](https://community.letsencrypt.org/u/danielwi)\
**Post date:** [October 21, 2024, 8:43pm UTC](https://community.letsencrypt.org/t/timeout-during-connect-likely-firewall-problem/227642/8 "2024-10-21T20:43:09Z")

</div>

Ok, the AAAA record values did not match. I adjusted it, so far no change but maybe it takes a moment until it's propagated...?

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [October 21, 2024, 8:43pm UTC](https://community.letsencrypt.org/t/timeout-during-connect-likely-firewall-problem/227642/9 "2024-10-21T20:43:51Z")

</div>

Those match the DNS. Did you change something? Because IPv6 is working now

Update: we cross-posted. Should work. What error message are you seeing now? Sometimes minor differences matter.

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [October 21, 2024, 8:44pm UTC](https://community.letsencrypt.org/t/timeout-during-connect-likely-firewall-problem/227642/10 "2024-10-21T20:44:10Z")

</div>

From my end IPv6 is all open now on port 80 and 443.

---

<div class="post-metadata">

**Author:** ![danielwi](https://avatars.discourse-cdn.com/v4/letter/d/b38774/32.png) [@danielwi](https://community.letsencrypt.org/u/danielwi)\
**Post date:** [October 21, 2024, 8:46pm UTC](https://community.letsencrypt.org/t/timeout-during-connect-likely-firewall-problem/227642/11 "2024-10-21T20:46:35Z")

</div>

Yes, I fixed the AAAA record. I myself still can't curl on ipv6. But the certificate could now be renewed! Thanks, guys!

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [October 21, 2024, 8:47pm UTC](https://community.letsencrypt.org/t/timeout-during-connect-likely-firewall-problem/227642/12 "2024-10-21T20:47:33Z")

</div>

> [@danielwi](#):
>
> I myself still can't curl on ipv6

From what device? Does it have IPv6 support?

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [November 20, 2024, 8:47pm UTC](https://community.letsencrypt.org/t/timeout-during-connect-likely-firewall-problem/227642/13 "2024-11-20T20:47:57Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
