Lets take example where OpenVPN is configured on the router.
Once OpenVPN configuration is saved, a new zone will appear in router's firewall:
As it could be seen, by default router will allow forward traffic between openvpn and lan zones.
If we select openvpn zone and press Edit, we could add or remove zones, or reject traffic forwarding for selected zone.
In this example inter-zone forwarding only have lan zone selected, which mean router's will allow traffic forward between openvpn and lan interface and vice versa.
But if we remove lan zone from allowed destination zone:
Router will reject traffic forward from openvpn zone as no allowed interface is selected and default zone forwarding rule is reject: