Drag and drop the definitions on the left to the corresponding configuration on the right. <DragDrop items={["destination zone","source zone","firewall policy","zone pair"]} slots={[{"answer":"source zone","id":"slot1","label":"grouping of VPNs where the data traffic flows originate"},{"answer":"destination zone","id":"slot2","label":"grouping of VPNs where the data traffic flows terminate"},{"answer":"firewall policy","id":"slot3","label":"matching condition that allows traffic flow between two zones"},{"answer":"zone pair","id":"slot4","label":"container that associates forwarding and blocking decisions"}]} explanation={"A source zone identifies where traffic enters or originates, and a destination zone identifies where it ends. Firewall policies match traffic and allow it between zones. Zone pairs group the forwarding and blocking behavior for traffic between zones.\n\n**Learn more:** [Cisco SD-WAN Zone-Based Firewall (ZBFW)](https://www.cisco.com/c/en/us/support/docs/routers/sd-wan/217758-cisco-sd-wan-zone-based-firewall-zbfw.html) · [Enterprise Firewall with Application Awareness](https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/m-firewall-17.html)"} reuse={false} />