You can configure ACL on NE20, but apply it on the interface by commands "packet-filter" or "firewall packer-filter" is impossible. There is no such commands in last software versions, i.e. NE20-VRP330-0521.04 and NE20-VRP510-1246.01
traffic classifier uplink
if-match acl 3000
traffic behavior deny
traffic policy uplink
classifier default-class behavior
classifier uplink behavior deny
ip address 192.168.232.2 255.255.255.252
traffic-policy uplink inbound
In new software versions there is trend to use module policy realizing the QoS and route policy. You should configure acl and then use it as classifier for QoS traffic policy which you can bind to the interface.
In new software versions there is trend to use module policy realizing the QoS and route policy.