At this time LXD ACL feature doesn’t work with routed NICs.
routed
See also Network ACLs possible on routed devices?