I am also seeing this bug on ISR4451-X running 16.06.05. The exact same IPs, when used in an object-group are ignored but work fine when referenced directly in the ACL rule. This fails: object-group network MGMT-NETS-NETGRP192.168.0.0 255.255.0.0 ...