Scanner
The Scanner screen tries to open a TCP connection to every port of a range on one host and lists the ports that accept. Use it to confirm which services are actually listening on a device — the control port of a projector, the web interface of a switch, the port your own service was meant to open — and, for services that greet first, what they say.
Responsible use
A scan connects to every port of the range. Scan only hosts you own or are authorized to test: on other networks a scan can trip intrusion detection and is often against the rules.
Scanning a host
- Enter the Host / IP: one host, an IP address or a name.
- Set From port and To port, or pick a Preset.
- Adjust Concurrency and Timeout (ms) if you need to.
- Leave grab service banners on to read what each service says first.
- Press Start scan.
A bar under the button shows how many ports have been tried, of how many, and how many are open. Open ports appear on the right as they are found. The scan ends when every port has been tried; Stop scan ends it earlier, and ports not tried yet are not tried. The fields are fixed while it runs.
| Field | What | Default |
|---|---|---|
| Host / IP | The host to scan. | 127.0.0.1 |
| From port, To port | The range, both ends included, 1–65 535. When the first is larger, they are swapped. | 1–1024 |
| Concurrency | How many connection attempts are open at the same time, 1–1024. | 400 |
| Timeout (ms) | How long to wait for each connection, 50–10 000 ms. | 500 |
| grab service banners | After connecting, wait up to 400 ms for the service to send something, and keep its first 256 bytes. | on |
A Concurrency or Timeout (ms) outside its range is brought into it when the scan starts.
Preset fills the range:
| Preset | Ports |
|---|---|
| Well-known (1–1024) | 1–1024 |
| Common (1–10000) | 1–10 000 |
| OSC range (8000–9100) | 8000–9100 |
| Full (1–65535) | 1–65 535 |
How long a scan takes
A port that accepts answers at once. A port that does not can cost up to the whole timeout: a firewall that drops connection attempts never answers, and on Windows even a refusal can take longer than the default timeout. So a scan of a host that answers nothing takes about:
ports ÷ concurrency × timeoutThe full range at the defaults: 65 535 ÷ 400 × 0.5 s ≈ 82 s. Raise Concurrency or lower Timeout (ms) to go faster; lower the timeout too far and a slow host's open ports are missed.
Reading the results
Open ports lists every port that accepted a connection, in port order:
| Column | What |
|---|---|
| Port | The open port. |
| Time | When it was found. |
| Banner | What the service sent first, line breaks turned into spaces, or —. |
A port that refused, and one that did not answer within the timeout, are both left out: the scanner does not tell closed from filtered. The list keeps up to 2000 open ports.
Only services that speak first have a banner — SSH, SMTP, FTP, many device control protocols. A web server waits for a request, so its port shows —. Grabbing banners makes each open port take up to 400 ms longer.
A connection the scanner opens is closed again at once. The scanner sends nothing on it.
With capture on, every open port is also in the Inspector, with its banner and the verdict open.
Related
- Storm — load on a port you found.
- UDP and TCP — talk to it.
- Troubleshooting