Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Did you applied the seperate access-list created for the control plane traffic to external interface?? Because on the external interface you should already have existing access-group for the inbound traffic right?