Thank you for upgrading to 3.9. There have been no changes in the algorithm to detect "received flows from unmanaged interface". If you feel you are receiving theses events more often than before, please open a support ticket for our development team to investigate. Include diagnostics and a packet capture on the port receiving the flows (port 2055 is default) for time range in which these events occur. We have created internal cases for changing where the links point to. These will be addressed in a future release.