ARP scan is possible only if you are on the *same subnet as the target* systems. On an **Ethernet** (802.3) and **WiFi** (802.11), you need to know the MAC address of any system before you can communicate with it. The MAC address is necessary for the link-layer header; the header contains the source MAC address and the destination MAC address among other fields. To get the MAC address, the OS sends an ARP query. A host that replies to ARP queries is up. If we want Nmap only to perform an ARP scan without port-scanning, you can use `nmap -PR -sn TARGETS`, where `-PR` indicates that you only want an ARP scan. Below is an example output of a host discover using ARP: ```shell pentester@TryHackMe$ sudo nmap -PR -sn 10.10.210.6/24 Starting Nmap 7.60 ( https://nmap.org ) at 2021-09-02 07:12 BST Nmap scan report for ip-10-10-210-75.eu-west-1.compute.internal (10.10.210.75) Host is up (0.00013s latency). MAC Address: 02:83:75:3A:F2:89 (Unknown) Nmap scan report for ip-10-10-210-100.eu-west-1.compute.internal (10.10.210.100) Host is up (-0.100s latency). MAC Address: 02:63:D0:1B:2D:CD (Unknown) Nmap scan report for ip-10-10-210-165.eu-west-1.compute.internal (10.10.210.165) Host is up (0.00025s latency). MAC Address: 02:59:79:4F:17:B7 (Unknown) Nmap scan report for ip-10-10-210-6.eu-west-1.compute.internal (10.10.210.6) Host is up. Nmap done: 256 IP addresses (4 hosts up) scanned in 3.12 seconds ```