Hi,
you can only populate a zone with unbound interfaces. It wouldn' t really make sense to have policies for single interfaces and at the same time compound interfaces (zones) - which one would take precedence?
And yes, the Handbook is somewhat misleading in this respect. I will send them a request for reviewing it (if I find the time...).
So for you, delete the policies where you use the interface(s), create the hub zone and create the zone policy. Decide whether you allow intra-zone traffic or not. Checking the option is the easiest way to do this. If you don' t you can always allow intra-zone traffic via a separate policy in which you could filter on service, time of day or UTM settings. This is straight from the Handbook.
Ede
"Kernel panic: Aiee, killing interrupt handler!"