It’s possible it could be a local firewall that is reaching out to their cloud for lists of bad IP addresses or domains or a local firewall that is configured from a cloud interface. The other case is it could be web application firewall or WAF which where a company intercepts traffic, drops malicious requests and forwards it to your actual web server
I would have thought eating and breathing from the same hole would have been in this release 😞 guess I’ll just have to wait till 3.0