Configure ACL to filter the routs from a network segment, but the IP route table still contains the route entries of the network segment.
After changing the mask in rule to inverse mask, such as:
rule normal deny source 126.96.36.199 0.0.255.255
Reconfigure filter-policy 2000 import in OSPF mode
It is required to filter the routes from network segment 188.8.131.52/16, but the rule in ACL to deny the network segment uses the mask as:
rule normal deny source 184.108.40.206 255.255.0.0
So it cannot filter the routes from network segment 220.127.116.11/16.
When configuring the rules of ACL, match the inverse mask.