I was thinking about how to use these more effectively and efficiently. I typically use an interface-list for WAN and MGMT but use firewall address-list for LAN segregation. Most of the time ether1 is the only interface in the WAN list so I am not sure what I am really saving. I suppose it is easier to think about?
My rudimentary understanding is that you can achieve similar things in the firewall but with interface-list you can specify an entire VLAN or physical interfaces. When using multiple VLANs perhaps this is easier to use rather than creating multiple FW address-lists. I also see others use the concept of trusted, untrused, internet_only, etc.. in their interface-lists which all seem like a valid approaches depending on your use case.
Do you create an interface-list for your LAN and use that as opposed to in or addition to firewall address-list? In general terms, how are you using these in your firewalls?