While migrating from a PfSense device to a Peplink 310, I noticed that configuration options for the firewall are a bit more convoluted than they could be.
It should be possible to define aliases for IPs, or groups of IPs to use in firewall rules in situations where IP ranges are inappropriate. It would also allow a single reference for a host to be updated should its IP change, rather than individually editing every rule it is used in.
Accounting PCs (allowed to access servers owned by our bank, to post transactions)
Bank Servers (on internet)