Drag the code snippets shown below into the configuration boxes to stop ICMP packets from the internet circuit from reaching VPN10 users at site 101. Some options will not be used. <DragDrop items={["protocol 58","protocol 2","accept","drop","protocol 1"]} slots={[{"answer":"protocol 1","id":"match_protocol"},{"answer":"drop","id":"sequence_action"},{"answer":"accept","id":"default_action"}]} template={"data-policy VPN10_Data_Policy\n vpn-list VPN10\n sequence 1\n match\n {{match_protocol}}\n source-ip 10.10.10.0/24\n action {{sequence_action}}\n default-action {{default_action}}"} explanation={"IPv4 ICMP uses Internet Protocol number 1; protocol 58 is ICMPv6, while protocol 2 is IGMP. Cisco SD-WAN data-policy action `drop` discards packets that match the sequence, and `default-action accept` permits all other packets.\n\n**Learn more:** [Cisco Catalyst SD-WAN centralized policy configuration](https://www.cisco.com/c/en/us/td/docs/routers/sdwan/26x-later/policies/policies-configuration-guide/sd-wan-centralized-policy/config-centralized-policies.html) · [Cisco localized data policy configuration examples](https://www.cisco.com/c/en/us/td/docs/routers/sdwan/26x-later/policies/policies-configuration-guide/localized-policy-title/localized_data_policy_configuration_examples_12232.html)"} reuse={false} />