Configure ACL to filter the routs from a network segment, but the IP route table still contains the route entries of the network segment.
After changing the mask in rule to inverse mask, such as:
rule normal deny source 220.127.116.11 0.0.255.255
Reconfigure filter-policy 2000 import in OSPF mode
It is required to filter the routes from network segment 18.104.22.168/16, but the rule in ACL to deny the network segment uses the mask as:
rule normal deny source 22.214.171.124 255.255.0.0
So it cannot filter the routes from network segment 126.96.36.199/16.
When configuring the rules of ACL, match the inverse mask.