I do not understand why this is not possible. I always create a zone for everything so if I later need to add another interface, I do not have to redo all the firewall policies, etc. In the fortigate, an interface can belong to a zone and you can also use the same interface for a VIP. Just change the fortimanager to let you select an interface! I dont see myself needing to use the same VIP on multiple fortigates because the IPs would be different anyway. Fortimanager is the most frustrating product I have used in a long time. 5.0.1 is a real nightmare for this as now they do not let you even mix single and multiple interfaces in a global zone. It makes copying policies, etc useless between firewalls with different interface counts. 5.0.0 at least let you map a single interface to a global zone without the single interface zone box checked but it had other issues which prevented us from using it. Now 5.0.1 fixes those issues but breaks way more basic functionality.