The AWS VPC CNI has only supported network policies since last august, are you sure you’re on a version of the vpc-cni that does anything with the project network isolation policies?
It looks like I'm on 1.15.1 of the VPC CNI. Is that version controllable when it's a rancher created EKS cluster? I may have missed the option where you can tell it which version to use.