The nmap Command Explained: Scanning Your Own Network the Right Way
nmap (“network mapper”) sends carefully crafted packets to hosts and reports what answers: which machines are up, which ports are open, what services and versions are running, and sometimes what operating system they use. It is the standard tool for checking what your network actually exposes, as opposed to what you think it exposes.
First: only scan what is yours
Scanning your own systems or ones you have written permission to test is normal administration. Scanning other people’s systems without permission can break computer misuse laws and your ISP’s or cloud provider’s terms, even if you never do anything else. Your home network, your servers, and your lab are fair game; the server down the road is not.
Install
sudo apt install nmap # Debian / Ubuntu
sudo dnf install nmap # Fedora
sudo pacman -S nmap # Arch
Discover hosts on your network
A ping scan finds which hosts are up without scanning ports:
sudo nmap -sn 192.168.1.0/24
The /24 covers 192.168.1.0 to 192.168.1.255; our IP addresses guide explains the notation. On a local network with sudo, nmap uses ARP and also prints each device’s MAC address and vendor, which helps identify that mystery device:
Nmap scan report for 192.168.1.42
Host is up (0.0031s latency).
MAC Address: B8:27:EB:12:34:56 (Raspberry Pi Foundation)
Scan ports on a host
nmap 192.168.1.42
By default nmap scans the 1,000 most common TCP ports. Port states:
| State | Meaning |
|---|---|
| open | A service accepted the connection |
| closed | The host replied that nothing is listening |
| filtered | No reply; a firewall probably dropped the probe |
| unfiltered | Reachable, but nmap could not tell open from closed (ACK scans) |
Choosing ports:
nmap -F host # fast: top 100 ports
nmap --top-ports 500 host
nmap -p 22,80,443 host # specific ports
nmap -p 1-1024 host # a range
nmap -p- host # all 65,535 TCP ports
Scan types
| Option | Scan | Notes |
|---|---|---|
-sS | SYN scan | Default with root. Sends SYN, never completes the handshake. Fast |
-sT | TCP connect | Default without root. Completes connections, so services log them |
-sU | UDP | Slow and less certain, but finds DNS, DHCP, SNMP, WireGuard |
-sn | Ping only | Host discovery, no ports |
-Pn | Skip discovery | Treat hosts as up, for hosts that block ping |
UDP deserves a mention: many security problems live on UDP ports (open DNS resolvers, SNMP with default communities), and they are invisible to TCP scans:
sudo nmap -sU --top-ports 50 192.168.1.1
Identify services and versions
Knowing port 8080 is open is less useful than knowing it is an outdated web admin panel:
nmap -sV 192.168.1.42 # service and version detection
sudo nmap -O 192.168.1.42 # OS detection
sudo nmap -A 192.168.1.42 # -sV, -O, default scripts, and traceroute
-A is noisy and slower but gives the fullest picture in one go.
The scripting engine
nmap’s NSE (Nmap Scripting Engine) runs hundreds of scripts for deeper checks:
nmap --script ssl-enum-ciphers -p 443 example.internal # which TLS versions/ciphers
nmap --script ssh2-enum-algos -p 22 host # SSH algorithms offered
nmap -sC host # the default safe script set
The ssl-enum-ciphers and ssh2-enum-algos scripts are handy for verifying your own hardening; see our SSH hardening guide.
Timing and output
nmap -T4 host # faster timing, fine on a reliable LAN
nmap -oN scan.txt host # normal output to a file
nmap -oX scan.xml host # XML for other tools
nmap -oA scan host # all formats at once
Timing templates run from -T0 (paranoid) to -T5 (insane). -T4 is a sensible default for your own network; higher levels can miss results on congested links.
A practical audit of a server
From another machine, check what your server really exposes:
sudo nmap -sS -sV -p- --open your-server.example.com
sudo nmap -sU --top-ports 100 --open your-server.example.com
Compare that with what the server itself says it listens on:
sudo ss -tulpn
Anything listening in ss but not visible to nmap is blocked by your firewall, which is good. Anything visible to nmap that you did not expect needs explaining. Our guides to checking open ports and firewall basics cover closing what should not be open, and the ufw rule builder helps write the rules.
Related tools
- tcpdump to see the actual packets nmap sends and receives
- netcat for testing a single port by hand
- Network troubleshooting commands for everything else
Frequently Asked Questions
Is it legal to use nmap?
Scanning networks and systems you own or have written permission to test is legal and a normal part of administration. Scanning other people’s systems without permission can violate computer misuse laws and your provider’s terms of service, even when no harm is done. Only scan what you are responsible for.
Why does nmap need root?
The default SYN scan crafts raw packets, which requires root or the CAP_NET_RAW capability. Without root, nmap falls back to a TCP connect scan using normal system calls, which works but is slower and more visible in the target’s logs. OS detection and UDP scanning also need root.
What does filtered mean in nmap results?
Filtered means nmap could not tell whether the port is open because something, usually a firewall, dropped its probes without replying. Closed means the host answered that nothing is listening. Open means a service accepted the connection.
How do I find all devices on my network?
Run a ping scan with nmap -sn followed by your subnet, for example nmap -sn 192.168.1.0/24. It lists every host that responds without scanning their ports. Running it with sudo on the local network also shows MAC addresses and vendors.
Why is a full port scan so slow?
Scanning all 65,535 TCP ports on many hosts sends a lot of probes, and filtered ports force nmap to wait for timeouts. Limit the scope with -F or —top-ports, scan fewer hosts, or use -T4 on a reliable local network to speed things up.
How is nmap different from ss or netstat?
ss and netstat run on a machine and list what that machine is listening on. nmap runs from another machine and shows what is actually reachable over the network, which includes the effect of firewalls. Using both tells you whether a service is listening and whether it is exposed.