Could not send report: Permission denied

Problem: I used foreman 1.16 and added a System 11.2-RELEASE-p3 FreeBSD 11.2-RELEASE-p3 #0: Thu Sep 6 07:14:16 UTC 2018. Everything works - the facts was installed, all the defined classes and so on. But the last step, which the client send the report to the server, i get the Error Message “puppet-agent: Could not send report: Permission denied”. i updated the puppet-server and foreman to the latest version, but without positive effect.
I have another Foreman System which works well, but i startet with Version 1.17.0
I also checked the output of the clients on both systems. the result was the same, but one send reports, the other one fails

puppet --version: 5.5.6

Expected outcome:

Foreman and Proxy versions: 1.19.0

**Foreman and Proxy plugin versions: 1.19.0

Other relevant data:
Debug: Dynamically-bound server lookup failed, falling back to report_server setting
Debug: Dynamically-bound port lookup failed; falling back to report_port setting
Debug: Failed to load library ‘msgpack’ for feature ‘msgpack’: cannot load such file – msgpack
Debug: Puppet::Network::Format[msgpack]: feature msgpack is missing
Debug: report supports formats: json pson yaml
Debug: Failed to load library ‘msgpack’ for feature ‘msgpack’: cannot load such file – msgpack
Debug: Puppet::Network::Format[msgpack]: feature msgpack is missing
Debug: report supports formats: json pson yaml
Debug: Failed to load library ‘msgpack’ for feature ‘msgpack’: cannot load such file – msgpack
Debug: Puppet::Network::Format[msgpack]: feature msgpack is missing
Debug: report supports formats: json pson yaml
Debug: Using cached connection for https://MY-HOST-ADDRESS:8140
Debug: Closing connection for https://MY-HOST-ADDRESS:8140
Error: Could not send report: Permission denied

it looks like some possible network or configuration issue on the affected system. perhaps try to see if you can connect from the host to the server at all at that port? are the ssl certificates set up properly?

Yes. All ports are available. It starts only with FreeBSD11.2

so i found out, that some IPFW rules seems to work a little other way in 11.2 as in 11.1.