I have a 2851 ISR Router and this router needs to act as a firewall. I do not have a firewall between my inside network and out internet. Can anyone tell me how to go about denying traffic from the outside to my inside network using a simple ACL while allowing all other traffic defined in my other ACL'S?
If you want to just permit a few things and deny everything else, you should avoid the permit ip any any.
The implicit deny will take care of everything not specified in the ACL as permit.
You need to careful because only traffic specified in the ACL will be able to pass through the router.
The IOS Firewall feature is nice because the router will allow traffic to pass through and allow the replies back even though they are not explicitly permitted in the ACL. So, the router keeps a stateful table for the connections (turn it into a sort of Firewall).