If this is related to audit/compliance scanning, then you will HAVE to white-list the scanner traffic past the "IDPS" features of the Palo Alto firewall. Additionally, just as someone else mentioned, you can not restrict to a list of "ports" that you will allow through security policy.
... View more