Configuring SNAT for Sophos, requires allowing /26 subnet to be set as source for source IP but SNAT only allows for one source IP.
Please explain what you are trying to do.
It looks to me that you are not doing this the correct way.
SNAT is for allowing incoming sessions to devices behind your firewall.
If you want to allow internal devices to get Sophos updates, then that is normally outgoing sessions.