Hello,
Did you try the wireshark trace to check if some ports were blocked ?
Normally you will need the dynamic RPC and also the 445 from you client to the CA maybe check that the 445 is open
https://learn.microsoft.com/en-us/archive/blogs/pki/firewall-rules-for-active-directory-certificate-services
Best Regards,