Did you whitelist your IP in csf?
If you didn't, and you removed the admin ports from csf's TCP_IN, then that might be the problem.
CWP doesn't use 8181, 8443, or 9090
dnsvj,com as the certificate for rocks.dnsvj.com installed, at that domain & SSL are working.
The SSL manager doesn't create and install subdomain certificates for a whole different domain and another.
That has to be done manually
I looked at
https://www.punjabrocks.com/, and the certificate is valid.
It just is having a problem with whatever is trying run on port 9988.
Best bet is to delete ALL the SSL certificates, USE the SSL Admin Panel to create them one by one for each domain name.
I'm also not sure if the Free Let's Encrypt SSL certificates will cover anything outside the normal ports (e.g. Web, FTP & Email)
Ports 2030, 2031, 2086, 2087, 2082, 2083 Do not respond, which points to a firewall issue.
If you can log into your CLI, run:
systemctl stop lfd
systemctl stop csf
Then try to login to the web interface.