ip mask bug?

first example:
pc1:192.168.2.14/24 pc2:192.168.2.15/24
firewall rules:
c:\windows\explorer.exe
1.block all

system
1.allow 192.168.2.20 in/out to 192.168.2.15 tcp/udp allport
2.allow 192.168.2.255 allport
3.block all

explorer.exe can’t use fileshare to pc2.if i change system rule:
1.allow 192.168.2.20/255.255.255.0 in/out to 192.168.2.21/255.255.255.0 tcp/udp allport
2.allow 192.168.2.255 allport
3.block all

so explorer.exe can use fileshare to pc2.and explorer open txtfile form pc2 ,notepad.exe open it.but firewall no prompt notepad.exe will access network.(firewall no notepad.exe rule).

second question:
in my network zones.set ip range .that show 192.168.2.11/192.168.2.200? ip range should use - not / ?

i use v4