I 'm pretty confident that shows up as a certificate error with it's own scare page, not connection reset. Usually on cert errors you can click through all the warnings and accept the risks to connect anyway. Connection reset is just a complete dead end.
I have pondered whether there's some way for the firewall to have a whitelist of sites that it allows without SSL MITM and otherwise sends reset for unknown SSL sites unless the firewall's MITM certificates are used. Our IT might be paranoid enough to do that.
I don't have any evidence that the firewall does any MITM other than I found it listed as a feature that can be configured on the firewall's website when I've been googling. But even then the error people complain about is bad cert not connection resets. I have tested with Chrome on systems that IT cannot have injected certificates into and they do work. I do know that I can access my home server's let's encrypt site using firefox and chrome without problems and the keys are correct. So it's not really high in my suspicion list.
Anyway it looks like I need to learn how to packet sniff.