Re: Zone, intra-zone trafic blocking and policy?
It seems to me like this should work, no problem. I've only done zone-to-zone rules once or twice, but it worked fine for me. Maybe there's something else going on related to the VPN specifically?
What do the logs tell you? I don't know if you have a FortiAnalyzer, but we log *everything* to it and it saves our bacon constantly when something goes wrong.