Tigershark, I agree with your methodology 100%. However In reccomending a tarpit I was just trying to be subjective to this thread. :) Now that I think about it, does'nt Cisco offer some type of protection against port scans? I forget the name of the feature but it basically causes the scans to be routed to a null address once it picks up that some distant IP is attempting to open connections to many ports in X amont of time.
Another great way to defend against Nmap scans is LIoIP (lethal injection over IP) ;)
