Hi,
Yes it is recommended to Install Only AV on the Servers. However, the reason why we don't recommend or we see the Proactive Threat Protection to be OFF on all the Server OS is because it's a (Behaviour) heuristics Scan. It not only Scans your file and folders on the disk, but also Scans the Temporary files in the Ram area based on their behaviour, thus impacting the performance of the system. So, the PTP is not designed for the Server's, its only for the Clients.
You may want to install Network Threat Protection on the Server's, provided the Firewall Rules are configured correctly for the Servers.
If you are running the latest release of SEP on your network, and you have NTP installed on the Server, I don't think the default Firewall policy should have a negative impact on the network.