Help with ACLs denying access

I’m trying to be good and set up ACLs. When my trunk provider connects (i.e. I’m placing a call from my cell phone to my Asterisk PBX, I get the message below. It looks like my ACL is defined correctly.

[Sep 16 12:18:31] NOTICE[30776]: acl.c:715 ast_apply_acl: SIP ACL: Rejecting ‘192.xxx.yyy.10’ due to a failure to pass ACL ‘internal’
[Sep 16 12:18:31] WARNING[30776]: res_pjsip_acl.c:130 apply_acl: Incoming SIP message from 192.xxx.yyy.10:5060 did not pass ACL test

sip*CLI> acl show internal

ACL: internal

0: deny - 0.0.0.0/0.0.0.0
1: allow - 192.168.1.0/255.255.255.0
2: allow - 192.xxx.yyy.10/255.255.255.255

The xxx.yyy part is an external IP. It is the expected IP. Everything works when I turn the ACL off.

From pjsip.conf:
[acl]
type=acl
acl=internal

I’ve also tried defining the ACL in just pjsip and same results.