Start Learning
Tutorials · Networking

Metasploitable 2 Nmap Scan Explained

Nmap is how you go from "I have an IP address" to "I know what's running on this machine." This walks through the three scans you'll run against Metasploitable 2 most often, and how to read what comes back.

Difficulty
Beginner
Estimated Time
15 minutes
Tools
Nmap (bundled with Kali Linux)
Prerequisites
Kali Linux and Metasploitable 2 on the same network
Tested Environment
Nmap 7.9x on Kali Linux
Learning Objective
Read an Nmap scan report like a security analyst
On This Page

Before You Start

You'll need Kali Linux and Metasploitable 2 on the same host-only network, and Metasploitable 2's IP address confirmed — see connecting Kali Linux and finding the IP address if you haven't done that yet. Every command below assumes 192.168.56.101 as the target; replace it with your actual address.

1. Confirm the Host Is Up

ping -c 4 192.168.56.101

Four replies confirm the network path works before you spend time on a full scan.

2. Run a Default Scan

nmap 192.168.56.101

Scans the 1,000 most common ports with no extra options. This is the fastest way to get a first look at what's exposed.

kali@lab-vm: ~
root@kali:~# nmap 192.168.56.101

PORT STATE SERVICE
21/tcp   open  ftp
22/tcp   open  ssh
23/tcp   open  telnet
80/tcp   open  http
445/tcp  open  microsoft-ds

3. Add Version Detection

nmap -sV 192.168.56.101

Adds an extra round of probing to identify the specific software and version behind each open port — this is the step that would reveal "vsftpd 2.3.4" on port 21, for example.

4. Scan Every Port

nmap -p- 192.168.56.101

Checks all 65,535 ports instead of just the common 1,000, which matters because a couple of Metasploitable 2's services (like the databases) live outside the default range.

Reading the Results

Each line in the output means: the port number and protocol, its state (open, closed, or filtered), and the service nmap associates with that port by convention. With -sV, a version string is appended. Treat the service name as a hint, not a certainty — it's based on the port number and a light probe, not a guarantee.

Security Lesson

Port scanning is almost always the first step of any security assessment, offensive or defensive. Learning to read a scan report accurately — without over- or under-interpreting what it shows — is one of the most transferable skills in this entire lab.

Common Problems

  • Scan returns nothing at all: confirm connectivity first with ping; a scan against an unreachable host looks identical to a scan against a fully filtered one.
  • Results differ from a tutorial's example output: normal — exact versions and even open ports can vary slightly between Metasploitable 2 releases and hypervisor configurations.

FAQ

Do I need to scan all 65,535 ports every time?

No. A default or top-1000-ports scan is enough for most exploration. A full -p- scan is worth running once to make sure nothing unusual is hiding on a high port.

Why does nmap sometimes show a port as "filtered" instead of open or closed?

Filtered means nmap couldn't determine the state, usually because something (a firewall rule) is dropping packets rather than responding. Metasploitable 2 has no firewall enabled, so this is rare against it.

Is it legal to run nmap against any IP address I want?

No. Only scan systems you own or have explicit written permission to test, such as your own Metasploitable 2 lab. Scanning systems without authorization is illegal in most jurisdictions.