Well, I don’t know what help are you exactly expecting here… Cisco ACLs don’t allow dynamic DNS hostnames, I’m not sure about the ACL limits itself now. You’d be better off to set up a proxy on some port with authentication, point your Avast clients to that proxy in settings and allow unlimited HTTP access from that proxy to web (and thus Avast update servers) on Cisco.