Can you try using hard-drop instead? 
code:device(config)# ip access-list extended ipv4-acl-example
device(conf-ipacl-ext)# hard-drop ip any 10.5.8.0 255.255.255.0
 
It's not clear on how you want to block the traffic. You want to apply the ACL at the VE to block hosts which are using that VE as their gateway from talking to other hosts on the same subnet? 
Also, please provide a bit more details ( hosts source and destination IP and topology).