The nmap Command Explained: Scanning Your Own Network the Right Way

The nmap Command Explained: Scanning Your Own Network the Right Way

nmap (“network mapper”) sends carefully crafted packets to hosts and reports what answers: which machines are up, which ports are open, what services and versions are running, and sometimes what operating system they use. It is the standard tool for checking what your network actually exposes, as opposed to what you think it exposes.

First: only scan what is yours

Scanning your own systems or ones you have written permission to test is normal administration. Scanning other people’s systems without permission can break computer misuse laws and your ISP’s or cloud provider’s terms, even if you never do anything else. Your home network, your servers, and your lab are fair game; the server down the road is not.

Install

sudo apt install nmap     # Debian / Ubuntu
sudo dnf install nmap     # Fedora
sudo pacman -S nmap       # Arch

Discover hosts on your network

A ping scan finds which hosts are up without scanning ports:

sudo nmap -sn 192.168.1.0/24

The /24 covers 192.168.1.0 to 192.168.1.255; our IP addresses guide explains the notation. On a local network with sudo, nmap uses ARP and also prints each device’s MAC address and vendor, which helps identify that mystery device:

Nmap scan report for 192.168.1.42
Host is up (0.0031s latency).
MAC Address: B8:27:EB:12:34:56 (Raspberry Pi Foundation)

Scan ports on a host

nmap 192.168.1.42

By default nmap scans the 1,000 most common TCP ports. Port states:

StateMeaning
openA service accepted the connection
closedThe host replied that nothing is listening
filteredNo reply; a firewall probably dropped the probe
unfilteredReachable, but nmap could not tell open from closed (ACK scans)

Choosing ports:

nmap -F host                 # fast: top 100 ports
nmap --top-ports 500 host
nmap -p 22,80,443 host       # specific ports
nmap -p 1-1024 host          # a range
nmap -p- host                # all 65,535 TCP ports

Scan types

OptionScanNotes
-sSSYN scanDefault with root. Sends SYN, never completes the handshake. Fast
-sTTCP connectDefault without root. Completes connections, so services log them
-sUUDPSlow and less certain, but finds DNS, DHCP, SNMP, WireGuard
-snPing onlyHost discovery, no ports
-PnSkip discoveryTreat hosts as up, for hosts that block ping

UDP deserves a mention: many security problems live on UDP ports (open DNS resolvers, SNMP with default communities), and they are invisible to TCP scans:

sudo nmap -sU --top-ports 50 192.168.1.1

Identify services and versions

Knowing port 8080 is open is less useful than knowing it is an outdated web admin panel:

nmap -sV 192.168.1.42        # service and version detection
sudo nmap -O 192.168.1.42    # OS detection
sudo nmap -A 192.168.1.42    # -sV, -O, default scripts, and traceroute

-A is noisy and slower but gives the fullest picture in one go.

The scripting engine

nmap’s NSE (Nmap Scripting Engine) runs hundreds of scripts for deeper checks:

nmap --script ssl-enum-ciphers -p 443 example.internal   # which TLS versions/ciphers
nmap --script ssh2-enum-algos -p 22 host                  # SSH algorithms offered
nmap -sC host                                             # the default safe script set

The ssl-enum-ciphers and ssh2-enum-algos scripts are handy for verifying your own hardening; see our SSH hardening guide.

Timing and output

nmap -T4 host            # faster timing, fine on a reliable LAN
nmap -oN scan.txt host   # normal output to a file
nmap -oX scan.xml host   # XML for other tools
nmap -oA scan host       # all formats at once

Timing templates run from -T0 (paranoid) to -T5 (insane). -T4 is a sensible default for your own network; higher levels can miss results on congested links.

A practical audit of a server

From another machine, check what your server really exposes:

sudo nmap -sS -sV -p- --open your-server.example.com
sudo nmap -sU --top-ports 100 --open your-server.example.com

Compare that with what the server itself says it listens on:

sudo ss -tulpn

Anything listening in ss but not visible to nmap is blocked by your firewall, which is good. Anything visible to nmap that you did not expect needs explaining. Our guides to checking open ports and firewall basics cover closing what should not be open, and the ufw rule builder helps write the rules.

Frequently Asked Questions

Scanning networks and systems you own or have written permission to test is legal and a normal part of administration. Scanning other people’s systems without permission can violate computer misuse laws and your provider’s terms of service, even when no harm is done. Only scan what you are responsible for.

Why does nmap need root?

The default SYN scan crafts raw packets, which requires root or the CAP_NET_RAW capability. Without root, nmap falls back to a TCP connect scan using normal system calls, which works but is slower and more visible in the target’s logs. OS detection and UDP scanning also need root.

What does filtered mean in nmap results?

Filtered means nmap could not tell whether the port is open because something, usually a firewall, dropped its probes without replying. Closed means the host answered that nothing is listening. Open means a service accepted the connection.

How do I find all devices on my network?

Run a ping scan with nmap -sn followed by your subnet, for example nmap -sn 192.168.1.0/24. It lists every host that responds without scanning their ports. Running it with sudo on the local network also shows MAC addresses and vendors.

Why is a full port scan so slow?

Scanning all 65,535 TCP ports on many hosts sends a lot of probes, and filtered ports force nmap to wait for timeouts. Limit the scope with -F or —top-ports, scan fewer hosts, or use -T4 on a reliable local network to speed things up.

How is nmap different from ss or netstat?

ss and netstat run on a machine and list what that machine is listening on. nmap runs from another machine and shows what is actually reachable over the network, which includes the effect of firewalls. Using both tells you whether a service is listening and whether it is exposed.