What are you reffering to exactly with "zones"? Are you talking about ZBF or an ASA with different interfaces that you call zones?
Either way: A VPN concentrator can be deployed with only one interface. Protected and clear traffic is entering and leaving the same interface in that scenario. The VPN concentrator is typically placed in a DMZ in these scenarios.
--
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.