Nmap may show closed ports on your server as opened if you are scanning from a natted system or behind a firewall. For example:
1720/tcp open H.323/Q.931?
3128/tcp open squid-http?
8080/tcp open http-proxy?
The following open ports showed opened on a system but were not listening on the server itself. It turns out it was a proxy from the ISP and the ports showed open on any server.