Linux / UNIX: Scanning network for open ports with nmap command

by on July 5, 2005 · 6 comments· LAST UPDATED August 12, 2007

in , ,

You can use nmap tool for this job. It is flexible in specifying targets. User can scan entire network or selected host or single server. Nmap is also useful to test your firewall rules. namp is metwork exploration tool and security / port scanner. According to nmap man page:
It is an open source tool for network exploration and security auditing. It was designed to rapidly scan large networks, although it works fine against single hosts. Nmap uses raw IP packets in novel ways to determine what hosts are available on the network, what services (application name and version) those hosts are offering, what operating systems (and OS versions) they are running, what type of packet filters/firewalls are in use, and dozens of other characteristics. While Nmap is commonly used for security audits, many systems and network administrators find it useful for routine tasks such as network inventory, managing service upgrade schedules, and monitoring host or service uptime.

nmap port scanning

TCP Connect scanning for localhost and network
# nmap -v -sT localhost
# nmap -v -sT

nmap TCP SYN (half-open) scanning

# nmap -v -sS localhost
# nmap -v -sS

nmap TCP FIN scanning

# nmap -v -sF localhost
# nmap -v -sF

nmap TCP Xmas tree scanning

Useful to see if firewall protecting against this kind of attack or not:
# nmap -v -sX localhost
# nmap -v -sX

nmap TCP Null scanning

Useful to see if firewall protecting against this kind attack or not:
# nmap -v -sN localhost
# nmap -v -sN

nmap TCP Windows scanning

# nmap -v -sW localhost
# nmap -v -sW

nmap TCP RPC scanning

Useful to find out RPC (such as portmap) services
# nmap -v -sR localhost
# nmap -v -sR

nmap UDP scanning

Useful to find out UDP ports
# nmap -v -O localhost
# nmap -v -O

nmap remote software version scanning

You can also find out what software version opening the port.
# nmap -v -sV localhost
# nmap -v -sV

A note about Windows XP / 2003 / Vista version

Windows user can find ipEye and IPSecScan utilities useful. Please note that Nmap also runes on Windows OS.

Read the man page of nmap for more information:
$ man nmap

TwitterFacebookGoogle+PDF versionFound an error/typo on this page? Help us!

{ 6 comments… read them below or add one }

1 ammaro May 18, 2008 at 6:18 am

thx for useful command


2 sv September 3, 2009 at 1:55 am

Very useful command to monitor network, Thanks a lot.


3 mohammed saud April 1, 2010 at 3:10 pm

Peace be upon you
I’ve got a problem in the net I’m Cat, a call from two to your web server does not work and if approached from the server to the device working I use 12 and Fedora before opened in Port modem did not work I would like you to help me in that not very much
In Fedora 12
ncat -v -l -p 62323
ncat -v -l -p 111
and from 1 to 4444
open port dosn’t work
please help me


4 Rajesh June 19, 2010 at 5:48 am

nmap -v -sT localhost ———gives the following output for me

Discovered open port 22/tcp on
Discovered open port 53/tcp on
Discovered open port 25/tcp on
Discovered open port 443/tcp on
Discovered open port 111/tcp on
Discovered open port 8080/tcp on
Discovered open port 80/tcp on
Discovered open port 3128/tcp on

22/tcp open ssh
25/tcp open smtp
53/tcp open domain
80/tcp open http
111/tcp open rpcbind
443/tcp open https
3128/tcp open squid-http
8080/tcp open http-proxy

I am not able to get gmail or yahoo mail to dhcp client. But I am able to get for clients with fixed ip…

Where I am wrong ?

I tried with Centos 5 and Fedora 13.
using squid Transparent proxy and dansguardian….

Any help is appreciated…



5 satish October 4, 2012 at 12:19 pm

this commands is very very useful please read everyone.


6 alireza seighalani December 27, 2012 at 4:48 pm


thanks man.

udp scan is -sU not -O . please double check.


Leave a Comment

Tagged as: , , , , , , , , , , , , ,

Previous post:

Next post: