Web server with a valid certificate via Ipfire

I’m asking because I need to get a web server up and running, ideally with a certified HTTPS certificate. Is it possible to get around Cerbot updating without its own IPv4 address? In other words, a server located in Green with remapped ports?

Thanks for your help.

This doesn’t answer your questions.

It is safer to place a web server in the orange DMZ network instead of green..

Yes, I could put it in Orange, but it would probably be the same problem.
A month ago, I was setting up a mail server, and there was a problem with Cerbot in Orange—Let’s Encrypt certification wasn’t working,
so I had to put the mail server on a separate public IPv4 address. So I assume there will be the same problem with Let’s Encrypt on the web server, but I won’t get another public address from my provider.

This may help:

PS - I have not tried this…

Thank you, that’s probably what I’m dealing with. I’ll look into it.

So, it’s sorted. I managed to negotiate one more public IPv4 address, and it’s no problem.