Custom Tag Security with Zones

I’ve configured Security Zones on the gateway to only allow read/write access on the local network.

When I go to setup tag security on my UDT I see it has a note that “leaving the zone blank means any security zone satisfies the requirement”.

I’m assuming that the gateway settings will trump any security zone setting on the individual tag, but I wanted to confirm first.

Yes, that is correct (assuming that the default security zone is set to read-only). Only tags that make it past the initial security check will have their individual permissions checked.