The fast way is to build those ports on your own using `poudriere` or something like that , that can also generate a repository configuration for you.
The painful way is to setup squid or nginx to cache anything for you, setup pkg to use squid/nginx and crawl through all packages, populating your cache mirror.
The best way is to simply not do it. If you can mirror, then you can access, and if you can access it, then where's the point of the mirror?
Also, most likely you aren't disallowed from obtaining, possessing or redistributing a copy of nmap, but instead you are disallowed to use it for malicious means, which you're not allowed to do anywhere else in the world, either.