Detect hosts, not limited by the LAN subnet or layer 2 networking.


To list hosts belonging to a certain subnet by setting the “-sL” switch

nmap -sL

For network discovery use the “-sn” switch

nmap -sn

ARP is a layer 2 protocol, it cannot discover systems through a router so when on the other side Nmap switches to ICMP requests which are layer 3; ARP within the local network, ICMP though the router.


Netdiscover is my preferred tool for local network discovery: it is pretty fast and offers the possibility to perform both active and passive ARP reconnaissance.

sudo apt-get install netdiscover
sudo netdiscover

sample output:

 Currently scanning:   |   Screen View: Unique Hosts                                                                                                                                                                         
 234 Captured ARP Req/Rep packets, from 1 hosts.   Total size: 15912                                                                                                                                                                         
   IP            At MAC Address     Count     Len  MAC Vendor / Hostname      
 -----------------------------------------------------------------------------     00:23:d0:1e:01:2f    234   15912  ASUSTek COMPUTER INC.