Trying to set up port forwarding on my router (FritzBox) for Home Assistant (Let’s Encrypt)

In order to set up Let’s Ecrypt on a Raspberry Pi 4 running Home Assistant, I am tring to set up port forwarding, because port 80 on the Raspberry Pi 4 (Home Assistant) must be reachable from outside when Let’s Encrypt creates a certificate.

In Let’s Ecrypt’s log, I read:

Certbot failed to authenticate some domains (authenticator: standalone). The Certificate Authority reported these problems:
  Domain: (mydoimain).duckdns.org
  Type:   connection
  Detail: (ip.ip.ip.ip): Fetching http://(mydomain).duckdns.org/.well-known/acme-challenge/something: Timeout during connect (likely firewall problem)
Hint: The Certificate Authority failed to download the challenge files from the temporary standalone webserver started by Certbot on port 80. Ensure that the listed domains point to this machine and that it can accept inbound connections from the internet.

I have verified my Raspberry Pi 4’s port 80 to be open for some seconds after Let’s Encrypt has this in its log:

Requesting a certificate for (mydomiain).duckdns.org

Namely, I get this:

$ nc -vz 192.168.1.194 80
homeassistant.fritz.box [192.168.1.194] 80 (http) open

I assume the problem is with my router. I have read that other services listening on port 80 might be a problem, but when I nmap my router using nmap to its outside URL, and with the port forwarding table empty, I get:

~$ nmap -Pn -p80,443,8123 (mydomain).duckdns.org
Starting Nmap 7.95 ( https://nmap.org ) at 2026-10-04 17:38 CEST
Nmap scan report for (mydomain).duckdns.org (ip.ip.ip.ip)
Host is up.
rDNS record for ip.ip.ip.ip: aftr-ip-ip-ip-ip.dynamic.(myprovider).de
 
PORT     STATE    SERVICE
80/tcp   filtered http
443/tcp  filtered https

Once I create a forwarded port in the router’s settings, namely port 80 (external) to port 80 of my Raspberry Pi 4 (HomeAssistant) for TCP, this is still the same. Even just after :


Requesting a certificate for `(mydomiain).duckdns.org`:

Shows up in the log, nmap has still the same output as above. However, nc shows a fwd/rev mismatch:

$ nc -vz (mydomain).duckdns.org 80
DNS fwd/rev mismatch: (mydomain).duckdns.org != aftr-ip-ip-ip-ip.dynamic.(myprovider).de

This leads me to believe that my ISP does something I need to consider when setting up DuckDNS (IPv4 / IPv6) or it is maybe a mistake to set up both IPv4 and IPV6 in the router’s port forwarding rules?


Update: Here’s one more thing that I don’t understand: My router lists only a few ports for provider’s services as open to the internet, namely:

5060
7078-7097
8089

However, when I nmap my ipv6 address, I get:

$ nmap -Pn -6 -p80,443 (ipv6:ipv6:ipv6:ipv6:ipv6:ipv6:ipv6:ipv6)
Starting Nmap 7.95 ( https://nmap.org ) at 2026-10-04 18:06 CEST
Nmap scan report for (ipv6:ipv6:ipv6:ipv6:ipv6:ipv6:ipv6:ipv6)
Host is up (0.00067s latency).
 
PORT     STATE  SERVICE
80/tcp   open   http
443/tcp  open   https

Why do ports 80 and 443 for http and https seem to be open even though my router does not list them as open? Is my ISP catching them, and are they thus unusable for me when I try to set up Let’s Encrypt via http, and do I need to choose dns instead in Let’s Encrypt’s settings?