This is not true. You could block intra-zone traffic and allow only
certain traffic inside the zone with policies, for example if you have
ZONE-A, use policy with source ZONE-A -> ZONE-A, e.g. control network
traffic inside the zone with source and d...