A handful of times yesterday and today I'm seeing port-probes from 66.175.217.0/24 which reverse to (numbers).census.ipinfo.io. A single ping last week from another IP in that range (something.ip.linodeusercontent.com) seemed to kick this off. No previous history with that /24 going back several years at least.
The ports being probed are 80 and 443 (so http and https) and also 500 (UDP) and 1194 (openVPN). Since these were being dropped (and logged) by my router, I must have had some reason to include this /24 as part of my router's web-server IP blocking list (IP's that don't hit my web server).
These IP's are part of /21 announced by AS63949 which is Akamai. So it would seem to me that Akamai is renting IP's to Linode.
Are enough people out there blocking Linode that they're now resorting to use Akamai IP's as cover?
If you're Akamai, why would you risk your reputation by doing that?
Cloudflare is increasingly doing stuff like this as well.