Configure ACL to filter the routs from a network segment, but the IP route table still contains the route entries of the network segment.
After changing the mask in rule to inverse mask, such as:
rule normal deny source 18.104.22.168 0.0.255.255
Reconfigure filter-policy 2000 import in OSPF mode
It is required to filter the routes from network segment 22.214.171.124/16, but the rule in ACL to deny the network segment uses the mask as:
rule normal deny source 126.96.36.199 255.255.0.0
So it cannot filter the routes from network segment 188.8.131.52/16.
When configuring the rules of ACL, match the inverse mask.