The Zone Protection doc here covers this Reconnaissance protection on page 4: It states: "Reconnaissance protection is used to prevent/alert administrators on reconnaissance attempts like ports scans, ICMP sweep. Unlike the flood settings, threshold settings are applicable to hosts in the zone where reconnaissance protection is configured.Interval: Time between successive probes for open ports. For host sweep it is the time interval between successive probes (ICMP/TCP/UDP) to the network" So, Since TCP uses SYN, that should count for TCP, and as far as other protocols ICMP and UDP they do not have SYN packets, but are covered by this protection, so that should also be covered. I hope that makes a little sense.
... View more