Ravindra BagaleCourses & study guides Track your progress

Guides

How to Use Nmap for Basic Network Scanning (Ethical Lab Only)

Nmap is a network scanner used to discover hosts and ports. Use it only on networks you own or have written authorisation to test (home lab, classroom range, signed pentest scope). This guide covers ethical framing and a few defensive, basic discovery commands — not exploit chains or attack playbooks.

Friends, Nmap is powerful — so law and ethics come first. Do not scan random public IPs. Lab, CTF range, or written permission. Today: basic host/port discovery in vertical steps — defender mindset. Unauthorised scanning is illegal in many places, including under US federal/state rules depending on context — when unsure, do not scan.

Quick answer

Ethical gate (all must be true):

  1. You own the network, or
  2. You have written permission that names the targets and dates, or
  3. It is an explicitly authorised practice range / CTF environment.

Then, on that lab only:

# Replace with YOUR lab subnet — example only
nmap -sn 192.0.2.0/24
nmap -sV -p 22,80,443 192.0.2.10
nmap -oA lab-scan-2026-09-29 192.0.2.10

Meaning:

  1. -sn — host discovery without a full port sweep.
  2. -sV -p … — version detection on ports you chose on one host.
  3. -oA — save normal/XML/grepable output for notes.

What do I need before this guide?

  • Written authorisation or a personal isolated lab (VMs on a private network).
  • Nmap installed on your lab workstation (nmap package on most Linux distros).
  • A notebook for scope and findings.
  • Course ethics chapter recommended first.

Why does ethical framing come before syntax?

Nmap only on your authorised lab Scan only networks you own or have written permission to test. Lab first, never a random public IP. Allowed Your home lab Written client scope CTF / practice range Not allowed Random public IPs Neighbour Wi-Fi No written OK

Scan only your own lab or targets named in written authorisation. Random public IPs and neighbour networks are out of scope.

  1. Scanning someone else’s systems without permission can be illegal and get you banned or worse.
  2. Defenders also use Nmap — knowing the basics helps you recognise scans in your own logs.
  3. Classroom skill = careful scope + clear notes + responsible disclosure paths at work.
  4. If scope is unclear, stop and ask in writing.

How do I run a basic authorised lab scan?

Step 1 — Write the scope on paper

  1. Target CIDR or host list.
  2. Allowed ports / excluded hosts.
  3. Start and end time.
  4. Who approved it (for non-owned networks).

Step 2 — Host discovery on the lab subnet

  1. Confirm you are on the lab network.
  2. Run a ping-style discovery only against the lab range:
nmap -sn 192.0.2.0/24
  1. Record which hosts responded.
  2. Do not widen the range “out of curiosity”.

Step 3 — Port and service basics on one lab host

  1. Pick one host from your scope.
  2. Scan a small explicit port set first:
nmap -sV -p 22,80,443 192.0.2.10
  1. Read open/closed/filtered states calmly.
  2. Save output:
nmap -oA lab-scan-2026-09-29 192.0.2.10

Step 4 — Timing and hygiene

  1. Prefer slower timing on fragile lab gear if packets drop (-T3 is a common default-like choice; avoid slamming tiny VMs).
  2. Do not disable systems that are out of scope.
  3. Keep raw outputs with your lab notes.
  4. Tear down temporary lab VMs when finished.

Step 5 — Think like a defender

  1. Ask: which of my production hosts would look like this?
  2. Close unused ports on your own servers (Linux harden checklist).
  3. Watch for unexpected scanners in your logs / SIEM lessons.

Ravindra Bagale's Tip

💡 "Just checking the neighbour router" — no. Curiosity is not a legal defence. Write your lab IP range on a sticky note. Do not skip the ethics chapter in the course. Stay alert!

How do I fix common Nmap lab problems?

Ghabru naka 😅 — these are the usual ones:

Symptom Likely cause Fix
All hosts “down” ICMP blocked in lab Try approved TCP host-discovery options from Nmap docs inside scope; fix lab firewall rules you control
Permission denied / need root Syn scan needs privileges Use TCP connect scans without root when learning, or run authorised sudo in lab
Huge noisy scan -p- on large ranges Narrow ports and hosts; respect scope
Tempted to scan the internet Out-of-scope curiosity Stop; use practice ranges only
Lost results No -oA Always save output with a date in the name

Try it at home

Build a tiny lab (two VMs). Write a three-line authorisation note to yourself, then:

  1. Run nmap -sn on that lab only.
  2. Run a short -sV on one VM.
  3. Paste open ports into notes and close one unused service on purpose.

Got it? Nmap is a powerful discovery tool. Not without permission / own lab. -sn, small -sV, save with -oA. Defender summary: close unused ports on your own gear. Ethics first, syntax second.

Frequently asked questions

Is scanning the public internet with Nmap OK?

Not without permission. Unauthorised scanning can be illegal. Use your lab or written scope only.

What is a safe first command in lab?

Host discovery with nmap -sn on your own lab subnet.

Why save output with -oA?

So you keep normal, XML and grepable results for notes instead of losing terminal scrollback.

Do I need root for every scan?

No. Many learning scans work without root; some techniques need privileges — stay inside lab policy.

How does this help defenders?

You learn what your own open ports look like and how noisy scans appear in logs.

Where are the course lessons?

Cyber ethics lab chapter and information-gathering Nmap lessons on this site.