> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Scanning IP-Hosts

> Searching address ranges for active systems without credentials—for a first overview of a network and for systems no other scan captures.

The *IP-Hosts* scan module searches address ranges for active systems, without
credentials. Use it for a first overview of an unknown network and to find
systems no other scan has captured. It requires a connected
[gateway](/docs/en/scan/gateway-install).

## Captured data

The scan is based on NMAP. *IP-Hosts* always scans intensively: besides
address, name and subnet mask, it tries to determine the network adapter's
vendor (from the MAC address), operating system, uptime and last boot. NMAP
estimates this information from the systems' responses and states an accuracy
in percent.

## Setting up the job

The wizard follows the standard path *Basics* › *Targets* › *Schedule* ›
*Summary*—see [Creating a Scan Job](/docs/en/scan/create-inventory).

In the *Targets* step each row carries only the *IP/Hostname* column—the scan
needs no credentials. The column takes a single address, a range, a network in
CIDR notation (e.g. /24) or a hostname, so a whole network fits into one row.

## Prerequisites

### Ports and protocols

The port scan checks different ports depending on the target, in the extreme
case all of them.

| Protocol | Port | Transport |
| - | - | - |
| ICMP (echo) | – | ICMP |
| Port scan (SYN) | variable | TCP |
| ARP—same subnet only | – | Ethernet |

### Permissions

* No rights are needed on the target systems.
* On the gateway computer, installing the Npcap driver requires local
  administrator rights.
* The antivirus software on the gateway computer allows NMAP to be called. Some
  vendors block NMAP when it is started from other software.

### Network requirements

* The Npcap driver is installed on the gateway computer. The gateway setup
  offers it, preselected. Without Npcap, extended information such as the
  operating system cannot be determined.
* The address ranges to be scanned are known.

<Warning>
  Npcap hooks into the network stack. Do not install the driver on a domain
  controller, Exchange server or a comparably critical system without checking
  first. It can compete with other packet filters, including other Npcap
  versions: Wireshark and PRTG bring Npcap or WinPcap with options of their own,
  and then both Wireshark and the scan may return wrong results.
</Warning>

## Common issues

| Symptom | Cause | Resolution |
| - | - | - |
| A whole address range does not find all systems; entered individually, they are found. | The firewall throttles ICMP (flooding protection). | Check the firewall's ICMP flooding protection setting. |
| Systems have no MAC address or a wrong one. | NMAP determines MAC addresses through ARP, and ARP requests do not cross routers. | Expected behavior. MAC addresses are available only for systems in the same subnet as the gateway. |
| Network monitoring raises warnings during the scan. | The scan sends many ICMP requests and deliberately invalid packets whose responses let NMAP recognize the operating system, for instance. | Expected behavior of an IP scan. |

## Related

After it is created, the job appears among the jobs; how you watch and adjust
it is in [Managing Jobs](/docs/en/scan/manage-jobs). Which scan modules exist for
the systems found is listed under [Scan Modules](/docs/en/scan/scan-modules).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.