Yes. If ' zone' stands for ' separate subnet' . There are no restrictions how you use the ports, that is, there are no ' dedicated' ports.
One detail though, some ports are Gigabit, and only some Gigabit ports use network processors to accelerate traffic. Thus, you can achieve wirespeed firewalling, or you could offload IPSec encryption/decryption to these NP ports. All other ' regular' traffic is processed by the CPU (AV, IPS, WF,...).
The raw power of the 200B is so comfortable that I had never to tweak these special ports for acceleration. Even with a lot of VPN tunnels CPU load stays below 5%. Of course, YMMV.
Now some personal opinion: the 300A is old iron. I' d never consider buying one these days. The newer line of Fortigates (310B/620B/1240B, 80C, 200B, 60C) offer line speed GbE firewalling, and partly high AV rates. And you' re right, at incredible low cost.
If you' d mentioned your old model I could be more specific but given the comparison between 300A and 200B I assume that you' re looking for a replacement with the power of at least the 300A. Then you' ll be 100% happy with a 200B, no doubt.
Ede
"Kernel panic: Aiee, killing interrupt handler!"