Well at least Security Zones allow you to match all traffic to or from an interface, and not have to maintain cumbersome groups listing all networks behind an interface for the anti-NAT rules. Used to be you were stuck maintaining these groups anyway for your "specific" anti-spoofing topology configuration, but with the addition of the "Network defined by routes" option in R80.20+ that has gone away as well.
Attend my online "Be your Own TAC: Part Deux" CheckMates event
March 27th with sessions for both the EMEA and Americas time zones