AWS AMI, Server unreachable when creating AIO instance

What IP address(es) do I need to resolve the error “The server is not reachable on Port 443. You can verify this e.g. with ‘’ by entering your domain there as ip-address and port 443 as port.” during AIO installation, at the “New AIO Instance” stage?

I’m installing Nextcloud AIO in AWS using the official AMI, in a secured environment, so we can’t do a blanket “allow all inbound” on https. I can access the server & AIO installation page via our vpn, and can allow access from specific IPs/address ranges, but not the entire internet.