Sorry, I think the zone alarm support on the newer clients 3.5.X and later have been confused with the ZA software being in the client iteself.
If the client was terminated on a vpn3000, the vpn3000 can enforce on the client ZA firewall use. See here for more details:
http://www.cisco.com/univercd/cc/td/doc/product/vpn/vpn3000/rel3_5_1/352_3con.htm#xtocid13
You would still need to buy ZA for the client, besides having the Cisco software. And then, the pix does not support this feature yet, of controlling the firewall being used by the client.
Hope this clarifies the issue for you.
Regards,