Linux nmap Command: Scan Authorized Hosts and Ports

nmap is a tool for investigating hosts and network ports. It is used to check open ports and service statuses on targets that you manage or have permission to inspect.

What is the nmap command?

In basic scan results, open means the target port is accepting connections, closed means it is accessible but there is no service listening, and filtered means it is difficult to determine a response due to a firewall or other reasons. You cannot determine the actual security or version of a service just by the port number.

Basic syntax

nmap [options] target

The installed implementation and available options may vary depending on the distribution. Use man nmap to check the documentation on your current system.

Examples

Checking your own computer

Learn the basic scan results of the local host without permission issues.

nmap 127.0.0.1

Restricting specific TCP ports

Narrow the target range to your own computer and two ports.

nmap -sT -p 22,80 127.0.0.1

Check only host discovery

Attempts host discovery on its own loopback address without port scanning.

nmap -sn 127.0.0.1

Reading results targeting my computer

Perform port scans only on targets you manage or have explicit permission to scan. For practice, use your own loopback interface instead of external addresses.

nmap -sT 127.0.0.1

Structure of the main columns to check in the output:

PORT     STATE  SERVICE
22/tcp   open   ssh

open means that a connection was accepted at that address and port. If there are no actually open ports, you may only see a summary of closed ports instead of a full table. Service names may be estimates based on port numbers, so do not assume the actual application. Fast, large-scale scans that can affect the network should first be checked against allowed scopes and operational policies.

Main Options and Format

Options/Format Description
-sT Scans using the TCP connect method.
-p list Explicitly restricts the ports to be scanned.
-sn Performs host discovery without a port scan.
-Pn Skips host discovery and assumes the target is alive.
-sV Guesses the service version of the port. Additional requests are generated.
-oN file Saves the results as plain text in a file.

Precautions when using

Do not scan others' networks without permission. Scanning wide address ranges, service version detection, and script scans increase traffic and detection events. Results depend on the time of the scan and firewall policies and therefore do not replace an inventory of operational assets or an actual security assessment.

Frequently Asked Questions

In Nmap, does 'filtered' mean the port is closed?

No. It means that the response was blocked or did not reach, making it difficult to determine whether the port is open or closed.

Official Documentation

You can check the exact behavior of the options and implementation differences in the official Nmap documentation.

More in This Category
Linux mktemp Command: Create Secure Temporary Files and Directories

Linux mktemp Command: Create Secure Temporary Files and Directories

Learn how to create unpredictable temporary files and directories with Linux mktemp, use templates and TMPDIR, clean up with trap, and avoid unsafe dry runs.

Linux tracepath Command: Trace a Network Path and Path MTU

Linux tracepath Command: Trace a Network Path and Path MTU

Learn how to trace a Network Path and Path MTU with the Linux tracepath command, including practical examples, key options, and important precautions.

Linux clear Command: Clear the Terminal Display

Linux clear Command: Clear the Terminal Display

Learn how to use the Linux clear command to clear the visible terminal screen and understand scrollback behavior, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux kill Command: Send a Signal to a Process ID

Linux kill Command: Send a Signal to a Process ID

Learn how to send a Signal to a Process ID with the Linux kill command, including practical examples, key options, and important precautions.

Linux Tutorial / Read Files with cat, less, more, head, and tail

Linux Tutorial / Read Files with cat, less, more, head, and tail

Learn when to use cat, less, more, head, and tail to read Linux files, with a small reproducible example and guidance for long files and logs.

Linux whoami Command: Show the Effective User Name

Linux whoami Command: Show the Effective User Name

Learn how to show the Effective User Name with the Linux whoami command, including practical examples, key options, and important precautions.

Linux Tutorial / PID and PPID Explained: Find and Manage Processes

Linux Tutorial / PID and PPID Explained: Find and Manage Processes

Understand what PID and PPID mean, inspect parent-child process relationships with ps and pgrep, and safely terminate a process you started yourself.

How to Check the Linux Distribution, Version, Kernel, and Architecture

How to Check the Linux Distribution, Version, Kernel, and Architecture

Learn how to identify a Linux distribution and version with /etc/os-release, then check the running kernel and CPU architecture with hostnamectl and uname. The guide also covers scripts, legacy systems, containers, WSL, and chroot environments.

Linux uniq Command: Remove or Count Adjacent Duplicate Lines

Linux uniq Command: Remove or Count Adjacent Duplicate Lines

Learn how to remove or count adjacent duplicate lines with the Linux uniq command, including practical examples, key options, and important precautions.

Linux dirname Command: Extract the Directory Part of a Path

Linux dirname Command: Extract the Directory Part of a Path

Learn how to use the Linux dirname command to remove the final component of a path and return its directory portion, with essential options, practical examples, output interpretation, and common troubleshooting tips.