Thank you to all…
The scan is the glinet wan ip.
I have 3 router: 1st Fritzbox fiber with inside no clients - 2nd router glinet for private lan witht the wan inside the 1st - and 3rd and last inside the 1st running opnsense firewall on proxmox. All traffic fom 1st router redirected as exposed host to the Opnsnese proxmox host.
I have scanned the public ip wan an i see the ports i have opened, the same for the opnsense firewall , but was unexpted to discover this problem on the wan glinet (lan) wan ip.
Scan of the public ip from another my server in germany. Scan of the two wan ip inside the main lan from test computer places inside the first lan to scan the two wan running with private ip. The two slave lans are physically divided to no have worries about security of the server with a lot of vps and private devices.
Private lans devices are connected with the server vlans vps using ondemand vpn