As soon as a NIC is defined as bridge port (in the current case enp2s0@vmbr0) it must not have configured an IP any more. Moreover, since you have just one network ip_forward is not necessary, VMs are contacted directly by layer 2 (i.e. via MAC address) from the router. Port forwarding to VMs...