Trusted VS Internal interface - Responsive Firewall

What is the difference between the Trusted Zone and the Internal Zone? My PBX is hosted off site at a cloud provider, so I dont have any “local” network to the PBX box. What is the best zone to put my local IP address in so I am never locked out of the PBX? I’ve been using the Trusted zone, but is Internal more secure or preferred?

as i understand it, all your interfaces should be marked as external. be sure to put the ip address of your computer you are logging in from into both the firewall whitelist (networks tab) and in the fail2ban list.