nmap is a great TCP SYN port scanner though! And since very little actually goes through UDP, its must better just to do an -sS scan and leave it at that...
If that doesn't return many open ports, then you can be "fairly certain" the system is "secure"
(Note the 2 sets of inverted commas in the above).