A practical reference for sysadmins using nmap to map attack surface, verify firewall configurations, and detect exposed services on Linux servers.
What is nmap?
nmap (Network Mapper) is the industry-standard open-source port scanner and network discovery tool. While it is widely associated with attackers performing reconnaissance, its most important legitimate use is the inverse: scanning your own servers from an external perspective to verify that your firewall rules are enforcing the access boundaries you intend. ss and netstat show what is listening from the inside — nmap shows what is actually reachable from the outside, after firewall rules have been applied. The difference between these two views is exactly where misconfigurations hide. A service listening on 0.0.0.0 that you believe is blocked by a firewall rule may still be reachable if the rule is incorrect, applied to the wrong interface, or overridden by a later rule. nmap discovers these gaps. It also performs service version detection, which identifies outdated software versions with known vulnerabilities — a critical input for patch prioritisation.
Syntax
nmap <target_ip>
nmap -sV <target_ip>
nmap -sV -p 1-65535 <target_ip>
nmap -sV -sC <target_ip>
nmap -Pn -sV <target_ip>
nmap -oN scan_output.txt <target_ip>Replace <target_ip> with your server’s public IP address — run from a machine outside your network. The -sV flag enables service version detection. -p 1-65535 scans all ports, not just the top 1000. -sC runs default NSE scripts for additional service probing. -Pn skips host discovery and treats the target as online — useful if ICMP ping is blocked.
Key Options and Flags
| Flag / Parameter | Description | Security Note |
|---|---|---|
-sV | Service version detection — identifies the software and version running on each open port | Reveals outdated software versions with known CVEs — essential for patch prioritisation |
-sC | Run default NSE scripts — additional probing for common misconfigurations | — |
-p 1-65535 | Scan all TCP ports, not just the default top 1000 | Malware and backdoors often bind to non-standard ports above 1024 to avoid default scans |
-Pn | Skip ICMP ping check — treat target as online regardless of ping response | Required if your server blocks ICMP — without this flag nmap may incorrectly report the host as down |
-oN <file> | Write output to a text file in human-readable format | Save scan results as a baseline to diff against future scans and detect new open ports |
-A | Aggressive scan: enables OS detection, version detection, script scanning, and traceroute | — |
--open | Show only open ports — filters out filtered and closed port noise | Cleaner output for security reviews — focus on what is actually accessible |
-T4 | Timing template 4 — faster scan, suitable for reliable networks | — |
Common Use Cases
Verify Firewall Rules from an External Perspective
After configuring iptables or ufw, confirm the rules are actually working by scanning the server from outside the network. This catches common mistakes: a DENY rule that was added after an ACCEPT rule, a rule applied to the wrong interface, or a service that bound to all interfaces after the firewall was configured.
nmap -sV --open <your_server_public_ip>Full Port Scan to Find Backdoors on Non-Standard Ports
Default nmap scans only the top 1000 ports. Backdoors and reverse shells typically bind to ports above 1024. A full port scan after a suspected compromise reveals any listening service that would not appear in a default scan.
nmap -sV -p 1-65535 --open <your_server_public_ip>Detect Exposed Services with Outdated Version Numbers
Service version detection reveals the exact software version running on each open port. Cross-reference with CVE databases or simply verify that your running versions match your latest patch deployment. An SSH server advertising an outdated OpenSSH version, or a web server still running a version with a known RCE, are immediate remediation priorities.
nmap -sV -p 22,80,443,3306,5432 <your_server_public_ip>Security Relevance: Attack Surface Mapping and Firewall Verification
The security value of nmap comes from its external perspective. Internal tools like ss and netstat show all listening services regardless of firewall rules — nmap shows only what an attacker on the internet can actually reach. This distinction is critical for verifying security posture. A server that has 15 services listening internally but only ports 22, 80, and 443 reachable externally has a correctly configured firewall. A server that has those same 15 services and shows 12 open ports externally has a misconfigured firewall. Running nmap against your own infrastructure before an attacker does is a fundamental practice. Many organisations discover open database ports, admin panels, and internal API endpoints that were accidentally exposed through firewall misconfigurations only after they appear in breach disclosures. Monthly nmap scans of your own perimeter, with results saved and diffed against the previous baseline, provide early warning of new exposures from deployments or configuration drift.
- Only scan servers you own or have explicit written permission to scan — unauthorised scanning is illegal in most jurisdictions
- Run nmap from outside your network or from a different cloud region to get an accurate external view, not from the server itself
- A filtered port in nmap output means a firewall is blocking it but the service may still be running — verify with ss -tulpn from inside
- Service version information exposed to the internet allows attackers to target specific CVEs — consider hiding version banners where possible
Practical Examples
External scan to reveal ports that should be closed but are not
nmap -sV --open -T4 <your_server_public_ip>The baseline external security scan. Run this after every major firewall change and compare the output against your expected open ports list. Any unexpected open port is a firewall misconfiguration or an unauthorised service.
Save scan results as a baseline for future comparison
nmap -sV -p 1-65535 --open -oN /tmp/scan_$(date +%Y%m%d).txt <your_server_public_ip>Saves the full port scan to a dated file. Compare against a previous scan with diff to immediately identify new open ports that appeared after a deployment or configuration change.
Quick scan of common attack-surface ports only
nmap -sV -p 21,22,23,25,80,443,3306,5432,6379,8080,8443,27017 <your_server_public_ip>Targets the most commonly exploited ports: FTP, SSH, Telnet, SMTP, HTTP, HTTPS, MySQL, PostgreSQL, Redis, alternate HTTP, HTTPS admin panels, and MongoDB. A fast sanity check that covers the majority of accidental exposure scenarios.
Troubleshooting Common Issues
Problem: nmap reports the host as down even though the server is running
Solution: The server is likely blocking ICMP ping. Add -Pn to skip host discovery: nmap -Pn -sV <target>. This treats the host as online and proceeds directly to port scanning.
Problem: The scan is very slow or timing out
Solution: Use -T4 for faster timing on reliable connections. For a full port scan (-p 1-65535), scans naturally take longer — 5-20 minutes depending on network conditions. If the server has rate limiting or fail2ban rules that block the scanning IP, reduce the scan rate with -T2 or whitelist your scanning IP in fail2ban’s ignoreip.
Problem: Scan results show ports as filtered rather than closed
Solution: Filtered means the port is blocked by a firewall but the host is not sending a TCP RST. This is the expected result of a correctly configured DROP rule. Closed means the host responded with a RST, indicating no firewall but no listening service. Both filtered and closed ports are inaccessible — filtered is the more secure configuration.
Summary
nmap is the definitive tool for external attack surface validation. Use it to verify that your firewall rules are working as intended, to detect service version exposure, and to baseline your external port footprint. Running nmap against your own server before an attacker does is a simple and highly effective security practice that catches firewall misconfigurations that internal tools cannot reveal.
- Always run nmap from outside your network — scanning from the server itself bypasses firewall rules and produces misleading results
- Save scan results with
-oNand diff against previous baselines to detect new exposures from deployments or config changes - A full port scan with
-p 1-65535is required to detect backdoors on non-standard ports — default scans only cover the top 1000
Related Commands
ss for fast open port enumeration • iptables for stateful firewall rules • ufw as a simplified firewall frontend • tcpdump for packet-level intrusion evidence
Is Your Linux Server Monitored 24/7?
INTRAM provides managed Linux hosting with continuous security monitoring, automated alerting, and expert response — so your team focuses on building, not firefighting.
Explore Managed Hosting