I will be glad if you can help me to compose an access list to block some address in my LAN (172.16.0.0/24). I want 172.16.0.1-172.16.0.65 to browse the internet and exclude all other address.
You don't have your access-list applied to an interface.
Create your access-list and apply like this:
ip access-list extended BLOCKWWW
permit tcp 172.16.0.0 255.255.255.192 any eq www
permit tcp host 172.16.0.64 any eq www
permit tcp host 172.16.0.65 any eq www
deny tcp any any eq www
permit ip any any
ip access-group BLOCKWWW in
This will only allow traffic to the web for the hosts you specified. It will allow everything else out.