thanks Denny,
the first PVE1 was static set to /24 the other was DHCP from zentyal at /32 (you cant define /24,says invalid)
Indeed changing the PVE2 to /24 static and only reserving in Zentyal did the trick.
agree on the firewall, just testing at the moment, Office 360 , teams , SSH and web...