OK then that's the way I guess I'll have to do it. I've got a ton of years of experience with Palo Alto and I really like the approach there. But ya, that's zones.
In my case I have created a firewall group of all local interfaces, called ALL_LOCAL. This gives an automatic alias of ALL_LOCAL net, which contains all the IPv4 and IPv6 subnets configured on those interfaces (and so changes with changes to those networks or interfaces in the group).