A friend of mine explain me what to do.
Solution 1: in each Zeroshell machine at the beginning and the en of the tunnel, you have to give an IP address to VPN interface: when you create the tunnel, in fact, you add a new interface. And this interface has no IP address.
These new IP adresses have to be in a new IP network (192.168.0.0/24 for example).
Solution 2: create a bridge: you select the VPN interface and the ETHxy that begins (or ends) the tunnel.
For each solution (1 or 2), don’t forget to create a static route.