OK This is the solution for your firewall rules on a loadbalancer for cell servers.
Do not use auto rules
Configure HTTPS access from External to vse (This is the vshield services iin this case loadbalancing)
Configure HTTPS access from the vse to the explicit IP addresses of your cell servers.
I believe this now means that your request comes into the vse (Vshield Edge) which then does the load balancing aspect before forwarding to the IP addresses you have specified for the cell servers.
There are NO Any Any configurations and the default rule is set to deny.
Hope this helps someone out there.