Thanks to Teltonika support for their assistance resolving this.
I post the solution here for anyone else having the same problem:
Under Network → Firewall → Attack Prevention
-
disable all options then then re-enable the ones you want
(I use all of them.
I’m not sure if step 1. is neccessary,
but I think it resets all paramaters to default,
so removes any other problems that may cause confusion.) -
Then specifically for the Port Scan section:
change Scan count from 5 / 10" to 20 or 30 / 10"
(20 worked but 30 was a little more robust).