Hi,
does XG understand destination networks with netmask like this?
It looks like but I would like to have confirmation from Sophos.
There is even a legacy Exception with this format (Apple).
So its supported. Another approach (in case you want to skip HTTPs Scanning) would be a TLS exception via DPI.