There are two major scanning techniques that are performed by organizations. These are internal and external vulnerability tests. You may think there is not really a lot of difference in them, but that is often a misconception. External scans look through the eyes of an outsider trying to come into your environment. So, they will interact with all the systems that are utilized by any public-facing services. This will include the public website and public-facing services as well. They are designed to test against whatever these external users have access to. So, the smaller your ACL is on your external firewall for inbound traffic, the smaller your attack surface will be. Always lock down your firewall to include only the necessary services and ports. External scans are typically tested via an approved scanning vendor, or ASV.
Internal scans, on the other hand...