Hi Guys!
As per my understanding of ZBF we need to create individual zone pairs for every zone that is , if i want to pass traffic from "IN-ZONE to "OUT-ZONE" i need a zone pair for it. Similarly for the return traffic of "IN-ZONE" to come back in , i need a class-map, policy-map and zone pair for "OUT-ZONE" as well??
I did a small lab in Packet Tracer where i inspected all ip traffic from my "IN-ZONE'' with a policy of pass and corresponding zone-pair where source was in-zone and destination was out-zone .
This allowed me ping and HTTP traffic to external networks

. which according to me should not be possible without a corresponding zone pair for out-zone??
where am i wrong??