RTFM -
Notwithstanding the fact that "they" are doing it to you, you need to bear in mind that such scanning may be illegal -- I say may, because although "unauthorised access" in an offence under the act, nobody has tested in court (to any significant extent) what actually constitues "unauthorised access"
um, I did say scan
yourself (as in 127.0.0.1). I'm guess that's authorized

but I could have worded it better. But don't try this at work without asking that friendly ... or otherwise ... sysadmin, folks.
I stand by what I said, though. I've learned an awful lot about network security by playing with some of these tools, and nmap is one of the most useful. Turn the firewall off and see what services you are offering to the outside world. Turn it on, port scan yourself, watch the firewall pick it up, then turn on SYN or FIN stealth and with some home favourites watch it do nothing...