Linux nmap Command: Scan Authorized Hosts and Ports

nmap is a tool for investigating hosts and network ports. It is used to check open ports and service statuses on targets that you manage or have permission to inspect.

What is the nmap command?

In basic scan results, open means the target port is accepting connections, closed means it is accessible but there is no service listening, and filtered means it is difficult to determine a response due to a firewall or other reasons. You cannot determine the actual security or version of a service just by the port number.

Basic syntax

nmap [options] target

The installed implementation and available options may vary depending on the distribution. Use man nmap to check the documentation on your current system.

Examples

Checking your own computer

Learn the basic scan results of the local host without permission issues.

nmap 127.0.0.1

Restricting specific TCP ports

Narrow the target range to your own computer and two ports.

nmap -sT -p 22,80 127.0.0.1

Check only host discovery

Attempts host discovery on its own loopback address without port scanning.

nmap -sn 127.0.0.1

Reading results targeting my computer

Perform port scans only on targets you manage or have explicit permission to scan. For practice, use your own loopback interface instead of external addresses.

nmap -sT 127.0.0.1

Structure of the main columns to check in the output:

PORT     STATE  SERVICE
22/tcp   open   ssh

open means that a connection was accepted at that address and port. If there are no actually open ports, you may only see a summary of closed ports instead of a full table. Service names may be estimates based on port numbers, so do not assume the actual application. Fast, large-scale scans that can affect the network should first be checked against allowed scopes and operational policies.

Main Options and Format

Options/Format Description
-sT Scans using the TCP connect method.
-p list Explicitly restricts the ports to be scanned.
-sn Performs host discovery without a port scan.
-Pn Skips host discovery and assumes the target is alive.
-sV Guesses the service version of the port. Additional requests are generated.
-oN file Saves the results as plain text in a file.

Precautions when using

Do not scan others' networks without permission. Scanning wide address ranges, service version detection, and script scans increase traffic and detection events. Results depend on the time of the scan and firewall policies and therefore do not replace an inventory of operational assets or an actual security assessment.

Frequently Asked Questions

In Nmap, does 'filtered' mean the port is closed?

No. It means that the response was blocked or did not reach, making it difficult to determine whether the port is open or closed.

Official Documentation

You can check the exact behavior of the options and implementation differences in the official Nmap documentation.

More in This Category
Linux clear Command: Clear the Terminal Display

Linux clear Command: Clear the Terminal Display

Learn how to use the Linux clear command to clear the visible terminal screen and understand scrollback behavior, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux cd Command: Change the Current Directory

Linux cd Command: Change the Current Directory

Learn how to use the Linux cd command to move between directories using absolute, relative, home, and previous paths, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux install Command: Copy Files and Set Attributes

Linux install Command: Copy Files and Set Attributes

Learn how to use the Linux install command to copy files while setting modes, owners, groups, timestamps, and destination directories in deployment scripts.

Linux type Command: Identify How a Command Is Resolved

Linux type Command: Identify How a Command Is Resolved

Learn how to use the Linux type command to identify aliases, functions, built-ins, keywords, and executable paths, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux killall Command: Signal Processes by Name

Linux killall Command: Signal Processes by Name

Learn how to signal Processes by Name with the Linux killall command, including practical examples, key options, and important precautions.

Linux ssh Command: Connect to a Remote Host Securely

Linux ssh Command: Connect to a Remote Host Securely

Learn how to connect to a Remote Host Securely with the Linux ssh command, including practical examples, key options, and important precautions.

Linux sed Command: Search and Replace Text Streams

Linux sed Command: Search and Replace Text Streams

Learn how to search and Replace Text Streams with the Linux sed command, including practical examples, key options, and important precautions.

Linux groups Command: Show a User's Group Memberships

Linux groups Command: Show a User's Group Memberships

Learn how to show a User's Group Memberships with the Linux groups command, including practical examples, key options, and important precautions.

Linux readlink Command: Inspect Symbolic Link Targets

Linux readlink Command: Inspect Symbolic Link Targets

Learn how to use the Linux readlink command to display symbolic link targets and optionally resolve canonical paths, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux ping Command: Test Host Reachability and Round-Trip Time

Linux ping Command: Test Host Reachability and Round-Trip Time

Learn how to test Host Reachability and Round-Trip Time with the Linux ping command, including practical examples, key options, and important precautions.