Reachability line · Host & Connection Checks
Host and connection checks: is it up, and who is it talking to?
“Is it up, and who is it talking to?”
Reachability line6 stops
- Angry IP ScannerAlso on Latency line
- LizardSystems Network Scanner
- TCPViewAlso on Throughput line
- SmokePingAlso on Latency line
- PingPlotterAlso on Latency line and Throughput line
- WiresharkAlso on Throughput line and Latency line
Some tickets are not about speed at all. A switch rebooted overnight and half the label printers did not come back. A power cut outlasted the UPS and nobody is sure which servers restarted cleanly. An application insists it cannot reach its database. The first question is binary — is it up? — and the second is who it is talking to. This line covers the tools that answer both on networks you administer.
Here, the evidence is a list with a timestamp: which addresses answered, how quickly, and what they identified themselves as, captured before and after a change so the difference is obvious. Angry IP Scanner and LizardSystems Network Scanner sweep address ranges. TCPView shows live connections on a single Windows host. SmokePing and PingPlotter keep watching a handful of critical targets, so you know exactly when something dropped off. Wireshark settles whether a host that “isn’t answering” is sending anything at all.
Range sweeps look a lot like reconnaissance to intrusion-detection systems, so this line comes with a firm rule: sweep only subnets you manage, tell whoever runs the security tooling, and keep each sweep to the ranges the ticket is about. None of these tools needs to go further than that to be useful.
6 host and connection tools side by side
Angry IP Scanner leads for its cross-platform reach and clean exports. LizardSystems Network Scanner follows for Windows networks where file shares matter, with the caveat that it has had no release since July 2021. The remaining tools cover single-host checks and continuous watching. Tap a tool name for our review; the vendor link goes to the developer’s site.
| Tool | Licence | Platforms | Evidence it produces | Key feature | Best for |
|---|---|---|---|---|---|
| Angry IP ScannerAnton Keks | Open source | Windows, macOS, Linux | A CSV/TXT/XML list of which addresses answered, with ping time and hostname | Fast multi-threaded sweep of a range with pluggable fetchers and export | A quick before/after list of which hosts answer on a subnet you manage |
| LizardSystems Network ScannerLizardSystems | Paid for business | Windows (vendor lists Windows 7 to 10 and Server 2008 R2 to 2016) | An HTML/TXT/XML export of hosts, their shares and read/write access | Online checks by ping or chosen ports, plus NetBIOS/SMB, FTP and web shares with access rights | Checking which Windows machines and file shares came back, and who can write to them |
| TCPViewMicrosoft Sysinternals | Freeware | Windows 8.1+ and Windows Server 2012+ | A live list of every TCP/UDP endpoint with its owning process, savable as text | Maps each connection and listening port to its owning process; Tcpvcon adds a command line | Finding which Windows process holds a port or keeps opening connections |
| SmokePingTobias Oetiker | Open source | Linux / Unix server (Perl + RRDtool), viewed in a browser | Weeks of latency and loss history drawn as "smoke" graphs, one per target | Long-term latency distribution graphs that show jitter, not just averages | Keeping a baseline so the next "it has been slow for days" ticket starts with data |
| PingPlotterPingman Tools | Commercial | Windows, macOS | Timeline graphs of latency and loss per hop that can be shared or exported | Continuous per-hop latency and loss graphed over time, with a shareable timeline | Proving an intermittent problem to an ISP with a graph instead of a description |
| WiresharkWireshark Foundation | Open source | Windows, macOS, Linux | A pcap file plus expert-info and TCP analysis (retransmissions, zero windows, resets) | Frame-level protocol decoding with TCP stream analysis and I/O graphs | Settling "network or application?" arguments with the actual packets |
Independent comparison — Scan 365 Pro is none of these vendors, and nobody paid for placement. Licences and platforms were checked against each vendor’s own pages on the date above.
How to choose
- Take a baseline before you need one
A sweep exported on a healthy Tuesday is the most valuable file you will have after an outage. Save one per subnet, with hostnames and response times, and refresh it after planned changes. Afterwards, the difference between two exports is your list of work.
- Do not trust ping alone
Windows Firewall blocks inbound ICMP echo on many profiles, and plenty of appliances ignore ping entirely. Add TCP checks on ports the host should be serving — 445 for file servers, 3389 for RDP hosts, 22 for Linux, 9100 for many printers — so a silent but healthy machine is not reported as down.
- Sweep at a sensible pace
On a local /24, a fast multi-threaded sweep finishes in seconds. Across a VPN, a small firewall or a remote site on a thin link, aggressive thread counts and short timeouts produce false negatives and can trip rate limits. Slow down, widen timeouts and sweep one range at a time.
- Watch the few hosts that matter continuously
Core switch, firewall, domain controllers, hypervisors, the main file server: these deserve a logging target in SmokePing or PingPlotter so you know when they dropped and for how long, not just that they are back now. That timeline is what a post-incident report needs.
- Check the licence for business use
Angry IP Scanner is GPL-licensed and free for any use. LizardSystems Network Scanner costs nothing for personal, non-commercial use, while any business deployment requires a per-machine licence, listed at $79.95 at the time of writing. TCPView is free under the Sysinternals licence terms. Confirm current terms on each vendor’s site.
After an outage: a sensible order of checks
Start with infrastructure — core switching, the firewall, hypervisor hosts — because everything else depends on them. Then sweep each affected subnet and compare the result with your last healthy export; the differences are your list. For anything missing, check the switch port and PoE status before assuming the device failed.
Next, check DHCP leases: a device that came back on a new address looks like one missing host plus one stranger. Finally, for services rather than boxes, confirm the port answers from the client’s side of the network, not just from the server itself. Our guide to checking which hosts came back after an outage turns this into a repeatable routine.
Vendor pages: Angry IP Scanner angryip.org · LizardSystems Network Scanner lizardsystems.com · TCPView learn.microsoft.com · SmokePing oss.oetiker.ch · PingPlotter pingplotter.com · Wireshark wireshark.org
Questions admins ask about host and connection tools
Why does a sweep show a host as down when I can still RDP to it?
The host is almost certainly dropping ICMP echo requests, which is the default for several Windows Firewall profiles. Add a TCP port check for 3389 or 445 in your scanner, or allow ICMP echo on the management network, and it will show as up.
Is Angry IP Scanner free for business use?
Yes. It is open source under the GPLv2, with no paid edition. Get it from angryip.org; the main Windows and Mac packages listed there include the Java runtime it needs, while the standalone Windows build expects Java 21 or later to be present.
Is LizardSystems Network Scanner still maintained?
Its latest release, 21.07, dates from July 2021, and the vendor’s supported-systems list stops at Windows 10 and Server 2016. It may still suit a Windows network where share permissions are the main concern, but check current compatibility with the vendor before buying business licences.
Will a network sweep set off our security tools?
It can. Endpoint protection and IDS products often flag range sweeps as reconnaissance. Tell the security team before you sweep, run from a known management host, and limit the scan to the subnets involved in the ticket.
What is the difference between a sweep and monitoring?
A sweep is a point-in-time list of which addresses answered. Monitoring repeats checks against chosen targets on a schedule and keeps the history. You want both: sweeps to find out what changed, monitoring to know when it changed.
Keep going
Disclosure: vendor links on this page go straight to each vendor’s own site and earn us no commission. See the affiliate disclosure.