On one of our affected servers I set the MTU to 1280 and the renew worked. This is good debug information for the Let's Encrypt team. I have reverted that server's MTU as a workaround is not a solution.
Thanks MaxHearnden for the suggestion and tomryder-inspirenet for doing an initial try with that HTTPS connection failures (timeouts) from validation servers - #11 by tomryder-inspirenet .