This resolution KB article provides detailed information about the behaviour of TCP flows when the No-SYN-Check option is enabled in the TCP flow settings and TCP-RST is configured within the security zone.
When you configure "no-syn-check" under security flow and TCP-RST under the source security zone, the "no-syn-check" option takes precedence. This means that, even if TCP-RST is configured in the source security zone; if the first packet is not a SYN, the SRX will allow the packet to pass without checking the SYN flag, effectively bypassing the TCP-RST configuration.
set security flow tcp-session no-syn-check set security zones security-zone untrust tcp-rst
set security zones security-zone untrust tcp-rst