It’s a 5 year old post, but in case someone else has the same issue:
It is the policy subpacket (as also mentioned here)
Click on “customize ruleset” and find the policy rule
And the use ctrl+F to find the two “APT” entries.
deselect both. Click Apply!
Now “apt update” should work again as expected.
(Tested in Debian 12 behind IPfire. - Although the IPS is only running on the RED interface and none of the internal ones.)