You should be able to set your interior-facing interfaces to "Defined by routes" for all gateways. On the vpnt interfaces, set those with anti-spoofing disabled. You exterior-facing interfaces (to internet) should remain as External. Interfaces facing local-attached LANs (networks with no downstream next-hop) should remain as "This network" (not a static group).
I've moved just about all my customers to this dynamically-calculated topology and life has been pretty good. We can do dynamic and static routing on both interior and VTI networks as needed. Yep, it works on VSX, too.
"Defined by routes" will consult the RouteD FIB every few seconds for topology calculation and keep your network flexible at all points. With R80.30+, you should almost(*) never have to use a hard-set group object to define topology anymore.
(*) Yes, "almost never"; no doubt someone has some special scenario, but this should be the exception rather than the rule now.