Performing scans is forbidden according to the ETH Acceptable Use Policy.
The following is a quote from Stephen Sheridan, head of IT network security (2019):
... scanning is actually forbidden, according to the ETH Acceptable Use Policy. As you may already know, besides netiquette, scanning can cause damage to the reputation of the institution and may even prompt ETH to become partially or wholly blocked toward other institutions.
Members wishing to perform operations such as scans may make use of a gray zone called the Open Net, which was set up by the ITS Data Networks group; access can be granted by the IT Services group of D-INFK.
We have one interface available with the IP address 192.33.90.80 (hostperrig1.inf.ethz.ch) bypassing the firewall. Access to it is provided in the form of a VM (dedicated strictly to the person using it) with an interface attached to this network. To receive one, please contact your ITC.
All scans should be registered on the NetSec website under https://netsec.ethz.ch/network-scans/, which is referenced in the DNS TXT record for the hostname.
Please see the masscan exclude list for a list of domains to avoid scanning, based on past experience.