That log card does not show traffic that "made it through". What happened is this:
1) There were a bunch of drops for traffic sourced from a Panama IP address, these drops were performed by Geo Policy which is part of the Access Control policy
2) There were more than 100 Geo Policy drops from the same source IP address in Panama to the same destination port within 30 seconds (default settings), this triggered the "Sweep Scan" IPS signature which is looking for large numbers of IP addresses being raked for the same destination port number (port 22 is a popular target)
3) The Detect log card was created showing the Sweep Scan was triggered based on all the Geo Policy drops; it is just an additive alert saying "hey there have been a bunch of drops all against the same destination port (sweep scan), take a look at this unusual activity".
The Sweep Scan signature itself does not actually block or allow anything, it is just a threshold that when reached triggers an extra logging alert.
Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com