Further expanding on the Zone concept, I created another diagram to demonstrate the layering that will be accomplished when the zones are implemented.
In effect, the ZONE-NETCORE becomes the underlying fabric that enables the other zones, in this series.
You certainly don’t need to secure your zones in this way and you can definitely just trunk your ZONES back to a firewall or router or a cluster of either, as indicated in this diagram. You can combine this diagram with the other and create clusters of zones, if you choose.
Trust becomes the deciding factor in the approach you take to zoning, followed by comfort with and understanding of the nuances of trunking versus routing. Often times, the idea that multiple zones are traversing the same physical link with only logical (software) separation is enough to drive implementations towards a routed model.