in our company we use FireWall-1 NG FP3 and we are looking for writing the existing rules differently, we have some objects with an internal interface and an external interface,i was asked to 'split' this object in two: one internal with the internal interface only and another one external with the external interface only, is it a good solution?
i suppose you use automatic nat on global properties, so i suggest you to create 2 differents objects, one for internal and one with external ip, and after untick auto-nat-rules, and recreate nat rules with both direction (verse and reverse rules).