Virtual VPN Interfaces
I suggest that adding a Site-2-Site VPN is assignable to a virtual interface (i.e. tunnel0) that is can be assigned to a zone.
This would make multiple VPNs much more manageable (especially if you cannot control the other end of the tunnel).
To make it even better, the tunnel endpoint could be assigned to a physical bridge or VLAN interface.