Cache of IPs that the proxy is allowed to connect to.
Populated by DNS resolution of allowed domains. When the domain allowlist
is active, TCP connections to IPs not in this cache are rejected, closing
the bypass where a guest connects directly to a hardcoded IP.