With VPN engine turned ON, the firewall adds auto-added rules for allowing the traffic to pass through. These access rules make it easier for the administrator to quickly provide access between VPN network and the necessary resources without manually adding each access rule from and to respective zones.
Please make sure that the display filters are set right while you are viewing the access rules:




NOTE: Any access rules added to or from VPN zone while the VPN engine is globally turned OFF will not be visible on the UI but gets added. You will be able to see them once you enable the VPN engine. Also, you will not be able to add address objects with zone VPN with the VPN engine being OFF.