Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Yep. It will log the flows that match each rule to the syslog server you have configured under Network Wide > Configure > General > Logging. If you don't have a syslog server set up, you should probably just set the logging to disabled for each rule....
Based on the information you gathered and assuming you need the rules because you're blocking other traffic later in the ruleset, you'd need two rules. Both with a destination IP of 74.125.250.0/24. One for TCP with destination ports 443 and another ...
One option that may work is would be to use a Group Policy (network wide > configure > group policies) for the special users that should be able to access the site. Put website.com/login in the whitelisted URL section for that group policy, but also ...