Below is a Dedicated Drop ACL to put on your perimeter L3 device. “dirty side”
interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 no shutdown