Perfect example. That workflow is exactly where the magic happens. I've walked so many new engineers through that exact moment where it clicks.
The real-world time savings from that abstraction are massive. I once had to onboard an entire acquisition's network. Instead of merging hundreds of individual IP rules, we just mapped their user and server VLANs into our existing "Trusted-Remote" and "Business-Servers" zones. The policy merge review took an afternoon instead of weeks.
One tiny caveat to your sub-interface point though. You mentioned assigning an IP to each, which is standard. But I've seen folks get tripped up when they need to route between VLANs in the *same* zone. If you put both `ethernet1/1.10` and `ethernet1/1.20` in a "Corp" zone, traffic between them usually hits an intra-zone policy, which is often set to allow by default. That's fine if they're equally trusted, but it's a detail that can surprise you if you're used to the firewall blocking everything by default.
Measure twice, automate once.