This article describes why users cannot select a zone "Any" in a global rule.
If you create a Global rule with 2 or more source zones and a destination zone as "any" or vice-versa as below:
Now, if you try to change the source zone for the rule to "any", drop down will not show "any" as below:
Please refer Add a Security Policy RuleIf the user has created a global rule with multiple zones in the source or destination endpoint and wants to edit the Source and Destination zone to ANY, then the user won't be seeing the zone ANY in the dropdown list. This is an expected behavior and the expected working of Security Director Cloud.If a user wants to configure zone "ANY", then the user can either remove the other zones, keeping the zone field blank which is equivalent to configuring the zone field as ANY or he can choose ANY as the zone when creating the rule by clicking add icon (+).