@janxdevil I think we could sort of do that but it'd be a bit awkward and I don't think we'd save anything. We do have one firewall that has a lot of subnets behind it, so in theory it would be a good candidate for a big prefix, but in practice we want to preserve our freedom to move some subnets to their own firewall if necessary (without renumbering things on them).
I guess we could use a prefix for the general firewall plus more specific routes for some.