Define scope before the command
Nmap discovers hosts and inspects network services. Install it from the official project or your distribution's trusted repository. Scanning your own lab is a useful way to learn; permission to visit a website is not permission to scan all of its infrastructure.
Record the target, allowed ports and time window. Use one lab computer rather than a wide network range for the first exercise. Do not include printers, medical devices or other fragile equipment in an exploratory scan.
Check installation
nmap --versionScan a small port set
Replace the example with the real IP of your authorised lab host:
nmap -sT -n -p 22,80,443 192.168.50.10The TCP connect scan can run without raw-packet privileges on common systems. The numeric option avoids reverse-DNS lookups. This checks a specific set of TCP ports; it does not test every protocol or prove the host has no vulnerabilities.
Read the state, not just the service label
Open means a service accepted the relevant connection/probe. Closed indicates the target responded but no service was available on that port. Filtered means Nmap could not establish the state because probes or responses were blocked or otherwise inconclusive.
The service column can come from a port-number database. Seeing http beside port 80 does not prove a particular web server or version is installed. Use application checks and an appropriately scoped version query when needed.
Verify in the lab
On a Linux target, compare with sudo ss -lntp. On Windows, use Get-NetTCPConnection -State Listen. Explain why a local listener might still be filtered or unreachable from the scan computer: bind address, host firewall and routing all matter.
If the host is reported down, confirm its address and connectivity before changing scan options. The separate port-check tutorial explains when a single-host -Pn test is appropriate.
Common mistakes
Using aggressive all-feature options at the start increases activity and complexity without answering the basic question. An open port is not automatically a vulnerability. A filtered result is not proof of a secure service. Record the vantage point and time so later comparisons are meaningful.
Keep useful notes
Write down the command, target, expected services and observed states. Remove temporary lab listeners after practice. The goal is an explainable network observation, not the largest possible scan output.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.