I assume that you use default config,
clone fedora-37-dvm / debian-11-dvm, rename it as app-sys-firewall
clone sys-firewall, rename it as sys-firewall-lab
change template sys-firewall-lab from fedora-37-dvm / debian-11-dvm to app-sys-firewall
configure your changes on app-sys-firewall.
start sys-firewall-lab.