What are you reffering to exactly with "zones"? Are you talking about ZBF or an ASA with different interfaces that you call zones?
Either way: A VPN concentrator can be deployed with only one interface. Protected and clear traffic is entering and leaving the same interface in that scenario. The VPN concentrator is typically placed in a DMZ in these scenarios.