SRX 300 Juniper Firewall

Based on the article given correct me if im wrong. You can put multiple zone to untrust ? For example i have 11 vlan, i can put 11 vlan and destination to untrust instead of doing it one by one correct ?

Thank you so much. I have tested on my client side and its working fine. Just need your advice, every vlan i put dhcp 100-200 and the subnet is /24. If i make certain device like printer to ip out of the range of 100-200 it will still got the internet access correct ?

and another issue is im able to ping from vlan to vlan but not the device that is connected to the vlan segment.

Example vlan 1 can ping vlan 3 gateway

172.16.88.1 can ping 192.168.3.1 but not 192.168.3.100 (lets say this is printer)

how do i make this possible so vlan 1 also can use printer at vlan 3

You can have multiple interfaces in the same zone. I use irb interfaces on my SRX and I have all my internal networks (irbs) in the same zone

Just one more quick question. For vlan to communicate with other vlan is it possible to use on the same zone ?

Lets say i create one zone (vlan) which contains all of my vlan and i declare vlan to vlan but the source and destination is different.

P.s I have already manage to have internet access thanks to your advice thank you.