Ask a narrow question
If an SSH service should exist on one server, you do not need to scan every address and port first. Define the target and expected service, then test only the relevant path. A version probe sends application-level traffic and deserves more care than a simple listener check.
Check reachability
nmap -sT -n -p 22,443 192.168.50.10Replace the lab address with your authorised target. If host discovery fails but you have confirmed that this one host is reachable and in scope, you can skip discovery for that target:
nmap -sT -Pn -n -p 22,443 192.168.50.10The -Pn option does not bypass a firewall. It tells Nmap to attempt the scan without first deciding the host is up through normal discovery.
Add a controlled version query
When the host and service can tolerate it:
nmap -sT -sV --version-light -n -p 22,443 192.168.50.10Version-light uses a reduced probe intensity. It still interacts with services and can be inconclusive. Avoid fragile equipment or an unreviewed production scope.
Save a useful record
nmap -sT -n -p 22,443 -oA lab-port-check 192.168.50.10This writes several output formats using the given basename. Store them privately because inventories and version information can be sensitive. Use a new basename or move prior output before another test to avoid confusing runs.
Interpret without overclaiming
A product banner can be hidden, misleading or reflect a distribution package with backported fixes. Do not declare a specific vulnerability from a version string alone. Check the vendor's advisory and the installed package or product build.
Verify the actual service
Use an SSH login or HTTPS request through the intended route. A TCP connection proves less than a successful authenticated application action. Conversely, an application failure can be caused by certificate or account settings even when the port is open.
Common mistakes
The name assigned to a port by Nmap is not identical to a confirmed product version. Local scanning and external scanning see different paths. Scanning all ports with multiple detection features makes results harder to interpret and may disturb services. Keep the smallest scan that answers your operational question.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.