Configure ACL to filter the routs from a network segment, but the IP route table still contains the route entries of the network segment.
After changing the mask in rule to inverse mask, such as:
rule normal deny source 184.108.40.206 0.0.255.255
Reconfigure filter-policy 2000 import in OSPF mode
It is required to filter the routes from network segment 220.127.116.11/16, but the rule in ACL to deny the network segment uses the mask as:
rule normal deny source 18.104.22.168 255.255.0.0
So it cannot filter the routes from network segment 22.214.171.124/16.
When configuring the rules of ACL, match the inverse mask.