TLS Certyficates and http Routes

Thank You for reply and will of help
Im fight with that 3 days now and Im very exhausetd …

Like I said everything working fine and if its working from outside

Let me tell You more
I got 2 servers inside LAN (joomla and ns8)

and connection is like this

Internet > Mikrotik > joomla (workin fine port 80 is open … LetsEncryp cert is enabled)

then I put ns8 and have to change redirect ports 80 and 443 on Mikrotik from joomla to ns8
but after that my domain is blind from outside (404)

so I consult tht problem with AI and it advice me to use reverse proxy, I got qnap so I enabled reverse proxy on QNAP
and voila everything working fine

everything except lets encryp cert

I think problem is with doubled Reverse proxies becuase treafik on ns8 is Reverse proxy too

still dont know why :

if joomla take coms from outside the ports 80 and 443 are open (I chcecked)
but if i change to ns8 get coms from outside … even if services working fine with qnap reverse proxy
ports 80 and 443 are closed from outside ! (I chceked that too) … how ?! is that so LetsEncrypt cant working to

second question
How I can enable upload valid cert manualy to default ?
I got only delete option in TLS cert settings

Greetings
and I am very grateful to you for all advice you send me

take care !