Scan 365 Pronetwork troubleshooting, reviewed

Reachability line · Host & Connection Checks

Host and connection checks: is it up, and who is it talking to?

“Is it up, and who is it talking to?”

Reachability line6 stops

  1. Angry IP ScannerAlso on Latency line
  2. LizardSystems Network Scanner
  3. TCPViewAlso on Throughput line
  4. SmokePingAlso on Latency line
  5. PingPlotterAlso on Latency line and Throughput line
  6. WiresharkAlso on Throughput line and Latency line

Some tickets are not about speed at all. A switch rebooted overnight and half the label printers did not come back. A power cut outlasted the UPS and nobody is sure which servers restarted cleanly. An application insists it cannot reach its database. The first question is binary — is it up? — and the second is who it is talking to. This line covers the tools that answer both on networks you administer.

Here, the evidence is a list with a timestamp: which addresses answered, how quickly, and what they identified themselves as, captured before and after a change so the difference is obvious. Angry IP Scanner and LizardSystems Network Scanner sweep address ranges. TCPView shows live connections on a single Windows host. SmokePing and PingPlotter keep watching a handful of critical targets, so you know exactly when something dropped off. Wireshark settles whether a host that “isn’t answering” is sending anything at all.

Range sweeps look a lot like reconnaissance to intrusion-detection systems, so this line comes with a firm rule: sweep only subnets you manage, tell whoever runs the security tooling, and keep each sweep to the ranges the ticket is about. None of these tools needs to go further than that to be useful.

6 host and connection tools side by side

Angry IP Scanner leads for its cross-platform reach and clean exports. LizardSystems Network Scanner follows for Windows networks where file shares matter, with the caveat that it has had no release since July 2021. The remaining tools cover single-host checks and continuous watching. Tap a tool name for our review; the vendor link goes to the developer’s site.

ToolLicencePlatformsEvidence it producesKey featureBest for
Angry IP ScannerAnton KeksOpen sourceWindows, macOS, LinuxA CSV/TXT/XML list of which addresses answered, with ping time and hostnameFast multi-threaded sweep of a range with pluggable fetchers and exportA quick before/after list of which hosts answer on a subnet you manage
LizardSystems Network ScannerLizardSystemsWindows (vendor lists Windows 7 to 10 and Server 2008 R2 to 2016)An HTML/TXT/XML export of hosts, their shares and read/write accessOnline checks by ping or chosen ports, plus NetBIOS/SMB, FTP and web shares with access rightsChecking which Windows machines and file shares came back, and who can write to them
TCPViewMicrosoft SysinternalsFreewareWindows 8.1+ and Windows Server 2012+A live list of every TCP/UDP endpoint with its owning process, savable as textMaps each connection and listening port to its owning process; Tcpvcon adds a command lineFinding which Windows process holds a port or keeps opening connections
SmokePingTobias OetikerOpen sourceLinux / Unix server (Perl + RRDtool), viewed in a browserWeeks of latency and loss history drawn as "smoke" graphs, one per targetLong-term latency distribution graphs that show jitter, not just averagesKeeping a baseline so the next "it has been slow for days" ticket starts with data
PingPlotterPingman ToolsWindows, macOSTimeline graphs of latency and loss per hop that can be shared or exportedContinuous per-hop latency and loss graphed over time, with a shareable timelineProving an intermittent problem to an ISP with a graph instead of a description
WiresharkWireshark FoundationOpen sourceWindows, macOS, LinuxA pcap file plus expert-info and TCP analysis (retransmissions, zero windows, resets)Frame-level protocol decoding with TCP stream analysis and I/O graphsSettling "network or application?" arguments with the actual packets

Independent comparison — Scan 365 Pro is none of these vendors, and nobody paid for placement. Licences and platforms were checked against each vendor’s own pages on the date above.

How to choose

  • Take a baseline before you need one

    A sweep exported on a healthy Tuesday is the most valuable file you will have after an outage. Save one per subnet, with hostnames and response times, and refresh it after planned changes. Afterwards, the difference between two exports is your list of work.

  • Do not trust ping alone

    Windows Firewall blocks inbound ICMP echo on many profiles, and plenty of appliances ignore ping entirely. Add TCP checks on ports the host should be serving — 445 for file servers, 3389 for RDP hosts, 22 for Linux, 9100 for many printers — so a silent but healthy machine is not reported as down.

  • Sweep at a sensible pace

    On a local /24, a fast multi-threaded sweep finishes in seconds. Across a VPN, a small firewall or a remote site on a thin link, aggressive thread counts and short timeouts produce false negatives and can trip rate limits. Slow down, widen timeouts and sweep one range at a time.

  • Watch the few hosts that matter continuously

    Core switch, firewall, domain controllers, hypervisors, the main file server: these deserve a logging target in SmokePing or PingPlotter so you know when they dropped and for how long, not just that they are back now. That timeline is what a post-incident report needs.

  • Check the licence for business use

    Angry IP Scanner is GPL-licensed and free for any use. LizardSystems Network Scanner costs nothing for personal, non-commercial use, while any business deployment requires a per-machine licence, listed at $79.95 at the time of writing. TCPView is free under the Sysinternals licence terms. Confirm current terms on each vendor’s site.

After an outage: a sensible order of checks

Start with infrastructure — core switching, the firewall, hypervisor hosts — because everything else depends on them. Then sweep each affected subnet and compare the result with your last healthy export; the differences are your list. For anything missing, check the switch port and PoE status before assuming the device failed.

Next, check DHCP leases: a device that came back on a new address looks like one missing host plus one stranger. Finally, for services rather than boxes, confirm the port answers from the client’s side of the network, not just from the server itself. Our guide to checking which hosts came back after an outage turns this into a repeatable routine.

Vendor pages: Angry IP Scanner angryip.org · LizardSystems Network Scanner lizardsystems.com · TCPView learn.microsoft.com · SmokePing oss.oetiker.ch · PingPlotter pingplotter.com · Wireshark wireshark.org

Questions admins ask about host and connection tools

Why does a sweep show a host as down when I can still RDP to it?

The host is almost certainly dropping ICMP echo requests, which is the default for several Windows Firewall profiles. Add a TCP port check for 3389 or 445 in your scanner, or allow ICMP echo on the management network, and it will show as up.

Is Angry IP Scanner free for business use?

Yes. It is open source under the GPLv2, with no paid edition. Get it from angryip.org; the main Windows and Mac packages listed there include the Java runtime it needs, while the standalone Windows build expects Java 21 or later to be present.

Is LizardSystems Network Scanner still maintained?

Its latest release, 21.07, dates from July 2021, and the vendor’s supported-systems list stops at Windows 10 and Server 2016. It may still suit a Windows network where share permissions are the main concern, but check current compatibility with the vendor before buying business licences.

Will a network sweep set off our security tools?

It can. Endpoint protection and IDS products often flag range sweeps as reconnaissance. Tell the security team before you sweep, run from a known management host, and limit the scan to the subnets involved in the ticket.

What is the difference between a sweep and monitoring?

A sweep is a point-in-time list of which addresses answered. Monitoring repeats checks against chosen targets on a schedule and keeps the history. You want both: sweeps to find out what changed, monitoring to know when it changed.

Keep going

Other lines

Disclosure: vendor links on this page go straight to each vendor’s own site and earn us no commission. See the affiliate disclosure.