What a gotcha... So I set up a new web server... including firewalls rules... Including one that blocks port 80 because HTTPS Good, HTTP Bad...
Completely forgetting that one of the sites is accessed via Cloudflare with TLS set to Flexible mode, meaning Cloudflare doesn't try to talk HTTPS with the origin server at all...
Not very "flexible" in my opinion, more flexibility would come from it trying HTTPS if HTTP fails. Or better yet, try HTTPS first and fail backwards to HTTP.