Lesson 1 of 2 in nmap · 2 min left in this chapter
Reading the Output, Not the Flags
Three port states, and the one everybody misreads.
1 min read
Not yet reviewed
Most nmap tutorials are a list of flags. The flags are the easy part — you can look them up. What takes practice is reading the output, and in particular knowing what the tool is telling you when it says a port is filtered.
Three states, and they mean different things
What nmap prints
22/tcp open ssh
80/tcp closed http
3306/tcp filtered mysqlWhat actually happened
open something answered and completed a handshake
closed the host answered, and said nothing is listening
filtered nothing came back at allclosed and filtered are not degrees of the same thing. Closed is an answer — the host is up and that port is empty. Filtered is silence, and silence has several causes.
That distinction is the whole lesson. A closed port tells you the machine is alive and reachable. A filtered port tells you that something between you and it dropped the packet, and you do not know whether the port is open, closed, or the host does not exist.
Note
"Filtered" is a statement about the path, not about the service. A firewall dropping traffic, a cloud security group, a network ACL, or your own outbound rules all produce it identically.
Trying it
Scan the host gateway.internal and find the one service that is answering on a non-standard port. Print the scan output.