Rather than the config, would be helpful to know your network topology (with, eg. some ip addresses) and which is your goal, what you want achieve, eg if forwarding between interfaces must be allowed or denied, globally, per ip…
P.S. how are now the firewall’s default policies ? allow or deny ?
Usually, I leave the output chain empty, (allows all) and I work on both input (packets for the ZS itself) and forward (packets which traversing the ZS, aka packet switching) chain.