We can ping every IP address on a target network and see who would respond to our ping (ICMP Type 8/Echo) requests with a ping reply (ICMP Type 0). Although this would be the most straightforward approach, it is not always reliable. *Many firewalls block ICMP echo*; new versions of MS Windows are configured with a host firewall that blocks ICMP echo requests by default. To use ICMP echo request to discover live hosts, we need to add the option `-PE`. The output below shows the result of a ICMP scan on the local subnet: ```bash pentester@TryHackMe$ sudo nmap -PE -sn 10.10.68.220/24 Starting Nmap 7.60 ( https://nmap.org ) at 2021-09-02 10:16 BST Nmap scan report for ip-10-10-68-50.eu-west-1.compute.internal (10.10.68.50) Host is up (0.00017s latency). MAC Address: 02:95:36:71:5B:87 (Unknown) Nmap scan report for ip-10-10-68-52.eu-west-1.compute.internal (10.10.68.52) Host is up (0.00017s latency). MAC Address: 02:48:E8:BF:78:E7 (Unknown) Nmap scan report for ip-10-10-68-77.eu-west-1.compute.internal (10.10.68.77) Host is up (-0.100s latency). MAC Address: 02:0F:0A:1D:76:35 (Unknown) Nmap scan report for ip-10-10-68-110.eu-west-1.compute.internal (10.10.68.110) Host is up (-0.10s latency). MAC Address: 02:6B:50:E9:C2:91 (Unknown) Nmap scan report for ip-10-10-68-140.eu-west-1.compute.internal (10.10.68.140) Host is up (0.00021s latency). MAC Address: 02:58:59:63:0B:6B (Unknown) Nmap scan report for ip-10-10-68-142.eu-west-1.compute.internal (10.10.68.142) Host is up (0.00016s latency). MAC Address: 02:C6:41:51:0A:0F (Unknown) Nmap scan report for ip-10-10-68-220.eu-west-1.compute.internal (10.10.68.220) Host is up (0.00026s latency). MAC Address: 02:25:3F:DB:EE:0B (Unknown) Nmap scan report for ip-10-10-68-222.eu-west-1.compute.internal (10.10.68.222) Host is up (0.00025s latency). MAC Address: 02:28:B1:2E:B0:1B (Unknown) Nmap done: 256 IP addresses (8 hosts up) scanned in 2.11 seconds ``` The scan output shows that eight hosts are up; moreover, it *shows their MAC addresses*. Generally speaking, we don’t expect to learn the MAC addresses of the targets unless they are on the same subnet as our system. The output above indicates that *Nmap didn’t need to send ICMP packets* as it confirmed that these hosts are up **based on the ARP responses** it received Below is a scan from a system that belongs to a different subnet. The results are similar but without the MAC addresses. ```bash pentester@TryHackMe$ sudo nmap -PE -sn 10.10.68.220/24 Starting Nmap 7.92 ( https://nmap.org ) at 2021-09-02 12:16 EEST Nmap scan report for 10.10.68.50 Host is up (0.12s latency). Nmap scan report for 10.10.68.52 Host is up (0.12s latency). Nmap scan report for 10.10.68.77 Host is up (0.11s latency). Nmap scan report for 10.10.68.110 Host is up (0.11s latency). Nmap scan report for 10.10.68.140 Host is up (0.11s latency). Nmap scan report for 10.10.68.142 Host is up (0.11s latency). Nmap scan report for 10.10.68.220 Host is up (0.11s latency). Nmap scan report for 10.10.68.222 Host is up (0.11s latency). Nmap done: 256 IP addresses (8 hosts up) scanned in 8.26 seconds ``` Because ICMP echo requests tend to be blocked, you might also consider *ICMP Timestamp queries* to tell if a system is online. Nmap uses timestamp request (ICMP Type 13) and checks whether it will get a Timestamp reply (ICMP Type 14). Adding the `-PP` option tells Nmap to use ICMP timestamp requests. Similarly, Nmap uses *address mask queries* (ICMP Type 17) and checks whether it gets an address mask reply (ICMP Type 18). This scan can be enabled with the option `-PM`. ```bash pentester@TryHackMe$ sudo nmap -PM -sn 10.10.68.220/24 Starting Nmap 7.92 ( https://nmap.org ) at 2021-09-02 12:13 EEST Nmap done: 256 IP addresses (0 hosts up) scanned in 52.17 seconds ``` Although, based on earlier scans, we know that at least eight hosts are up, this scan returned none. The reason is that the target system or a *firewall* on the route is *blocking this type of ICMP packet*. Therefore, it is essential to learn multiple approaches to achieve the same result. If one type of packet is being blocked, we can always choose another to discover the target network and services.