I believe you are using Bulk Configurator from InControl2? If so, it is depending on the settings from the configuration file you uploaded into InControl2.
No, didn’t use bulk configurator. Unless importing firewall rules from exported config when first setting up InControl is considered “bulk configuration”.
Then, this is strange since Bulk Configurator is not using. I have no idea why the exempted subnets of Content Blocking are affected by InControl2. I did few tests here but was unable to reproduce the issue. Maybe you can help to open a ticket for us to take a look?