Yes the rule will be ignored. When anything other than "Any" is placed in the VPN column it adds an additional matching criteria. Based on the VPN Domains or IP routing into a VTI, in addition to matching the Source/Dest/Service fields, the traffic must be encrypting into a tunnel of that community or decrypting from a tunnel of that community. Traffic going in the clear or going in/out of a different community based on VPN Domains/VTI routing will not match that rule, even if all other rule fields such as Source/Dest/Service are a match.
This condition does not cause a policy verification or validation error. It is a common misconception that the VPN column is used to define what traffic is "interesting" to a VPN in regards to encryption which is not correct, the VPN Domains/VTI routing process does that.
New 2-day Live "Max Power" Series Course Now Available:
"Gateway Performance Optimization R81.20" at maxpowerfirewalls.com