@user_3357111 hi!
Ahe additive
vpn-instance at the end of the rule has a different function on the AR router and NE05.
In the case of an AR router, the vpn-instance parameter specified is only applied to firewall and IPSEC features, while on NE05, the parameter indicates the L3VPN what the traffic belongs to.
If the traffic is from L3VPN, this option must be configured in ACL.
If this option is not configured, it indicates that the traffic belongs to the public network, rather than L3VPN.