I was posed a question and am not sure of the answer.
Can you assigne separate zones to subinterfaces on the same intface with ZPF?
In other words, if I have 3 subinterfaces leaving one physical interface on a router, can I have 3 separate zones?
The rule states that there can be only one zone per interface, but is that physical, virtual, or either?
Yes you can setup that ( one zone per sub-interface)
I have a similar question, but in another way:
I have 2 sub interface in a single physical interface.
If I set this PHYSICAL interface into a zone, will the zone policies be valid for all sub interfaces? Or do I have to explicitly set each sub interface to the same zone?
Create your zones:
zone security lan1 zone security lan2 zone security lan3 ...
On your sub interfaces:
interface GigabitEthernet0/1.1 zone-member security lan1 ! interface GigabitEthernet0/1.2 zone-member security lan2 ! interface GigabitEthernet0/1.3 zone-member security lan3 ! ...