Hi,
Yep, the only ACL is the named extended list, which is applied on the outside interface in the overload command. I could have probably left them in place, I found this "alternate" solution with the named extended list as it is now, and then after that didn't work either I went to the cable...