ICMP IP Network Scanning / Probing using a Shell Commands

Posted on last updated January 29, 2008

Q. How do I check security of my network by running ICMP IP Network Scanning under FreeBSD / Linux? How do I subnet broadcast addresses? All I wanted to see if my firewall is working or not.

A. Internet Control Message Protocol (ICMP) one of the core protocols of the Internet protocol suite. It is chiefly used by networked computers’ operating systems to send error messages—indicating, for instance, that a requested service is not available or that a host or router could not be reached.

ICMP IP Network Scanning with nmap tool

You can use regular open source tool called nmap. Type the following command to run ICMP IP Scan:
$ nmap -sP -PI

Starting Nmap 4.20 ( http://insecure.org ) at 2008-01-29 23:40 IST
Host appears to be up.
MAC Address: 00:18:39:6A:C6:8B (Cisco-Linksys)
Host appears to be up.
Nmap finished: 256 IP addresses (2 hosts up) scanned in 5.746 seconds


  • -sP : This option tells Nmap to only perform a ping scan (host discovery), then print out the available hosts that responded to the scan. This is also known as ping scan.
  • -PI : This open tells Nmap that we are sending ICMP echo requests