As requested I contacted my hosting company, here’s the reply:
10.168.1.23 is the internal (private network) IP of one of our load balancers. The IP of the client making the request is in the HTTP_X_FORWARDED_FOR header: 192.0.84.33. This is a false positive in the plugin, so probably something you would ignore.
Looks like BPS Pro Plugin Firewall may not work with my particular hosting setup. Other plugins have the ability to work behind a proxy (i.e Limit Login Attempts) – is this not possible with BPS Pro?