ACL config applied over interface(vNIC) will take precedence and override the port-group config is an expected bahavior. If the config applied thru interface(vNIC) is removed then the config present in port-group will be applied.Thanks.
Hi,As Louis suggested you can add the data VLANs used by your VM in the same System-Uplink Port-Profile, which you have assigned to vmnic1. (For E.g. add "switchport trunk allowed vlan add <data-vlan1,data-vlan2...>" to your System-Uplink Port-Profil...