3.2.2 Set inbound 'ip access-group' on the External Interface
Information
This command places the router in access-list configuration mode, where you must define the denied or permitted access conditions by using the deny and permit commands.
Solution
Apply the access-group for the external (untrusted) interface hostname(config)#interface {external_interface} hostname(config-if)#ip access-group {name | number} in