Thanks, Steve. Much appreciated!
In this case, I think maybe you should not allow syntax like "from-zone global to-zone global" and a zone called global. We have customers that configured rules with this contextual policy, but they have not assigned any interfaces to this zone. What is the expectiation? When will this policy be used? For traffic from all interfaces that are not assigned to any other zones or simply never?