On one of our XGS-firewalls, we need a NAT rule for HTTP/HTTPS. On this firewall, it's not possible to create or renewal a Let's Encrypt Cert.
We need to disable the NAT rule, then it works to create/renewal the certificate.
But this can't be the solution, so we have to disable this rule manually all 60 days for a night.
Sophos should fix this: the cert-creation/renewal should have the priority before the NAT rule for HTTP/HTTPS.
Added TAGs
[edited by: Raphael Alganes at 10:13 AM (GMT -8) on 4 Dec 2024]