Somebody wants the printer VLAN re-addressed by Friday, and the only “documentation” is a DHCP scope that also leases to things nobody remembers plugging in. Before you touch a single static address, you want a list: which IPs answer, what they call themselves, what MAC is behind each one, and whether anything is listening on the ports that matter. Angry IP Scanner gets you that list in a few minutes and writes it to a CSV you can sort, diff and attach to the change ticket.
This walkthrough assumes a Windows admin workstation, one /24 VLAN, and Angry IP Scanner 3.10.0 (the current release at the time of writing). Everything below applies only to networks you own or are explicitly authorized to scan — see the note in step 1.
Before you start
- Authorization. Use with authorization only. Even an ICMP sweep plus a handful of TCP connects will show up in an IDS or a managed firewall’s logs. Get the range written into the ticket, and tell whoever watches the SOC console.
- Where you sit matters. MAC addresses come from your machine’s ARP cache, so they only resolve for hosts on the same Layer 2 segment. If you scan VLAN 30 from a laptop on VLAN 10, you get IPs and names but no MACs (or the router’s MAC for everything). Plug into a VLAN 30 access port, or run the scan from a jump host that has a leg in it.
- The tool. Get Angry IP Scanner from the project’s own site (angryip.org) or its GitHub releases page — our where to get it safely page lists what to check. Since 3.10.0 the Windows build bundles its own Java runtime, so you no longer need a JRE on the laptop. There is also a standalone Windows build that runs without an install step, which suits a USB toolkit.
Step-by-step: the GUI route
-
Enter the range. Leave the feeder on IP Range and type the first and last address, e.g.
10.20.30.1to10.20.30.254. You can also paste a CIDR block into the IP Range field’s netmask drop-down (/24) and let it compute the ends. -
Choose your columns. Open Tools → Fetchers. For an inventory sweep the useful set is Ping, Hostname, MAC Address, MAC Vendor and Ports. Add NetBIOS Info if the VLAN is full of Windows boxes; drop it for printers and IoT, where it only adds timeouts.
-
Pick the ports. In Tools → Preferences → Ports, replace the default list with the handful that tells you what a device is:
22,80,443,445,515,631,3389,9100That catches SSH-managed gear, web UIs, SMB, LPD/IPP/raw printing and RDP. Keep it short; every extra port multiplies connect attempts across 254 addresses.
-
Fix the ping method. In Preferences → Scanning, the default ICMP echo misses any Windows host with the stock firewall profile. If you care about those, switch to a combined UDP+TCP probe, or tick the option to scan dead hosts so the port probes still run. Expect a slower sweep when you do.
-
Run it. Press Start. On a typical /24 with a few dozen live hosts, a sweep with eight ports finishes in well under a couple of minutes on default thread settings.
-
Filter to live hosts. 3.10.0 already defaults the display to Alive only; confirm the drop-down at the bottom says so, or pick Open ports if you only want hosts that answered on something in your list.
-
Export. Use Scan → Export all and choose a
.csvfilename. The format is picked from the extension, so.txtor.xmlworks the same way. The CSV has a header row with your fetcher names (IP,Ping,Hostname, …) and uses standard comma delimiting with RFC 4180 quoting.
Step-by-step: the command-line route
The GUI is fine once. If you want the same sweep every Monday — or before and after a change window — use the command line. The syntax is [options] <feeder> <exporter>:
# Adjust the path to wherever ipscan.exe lives on your workstation
$ipscan = "C:\Tools\AngryIP\ipscan.exe"
$stamp = Get-Date -Format "yyyyMMdd-HHmm"
& $ipscan -f:range 10.20.30.1 10.20.30.254 -o "C:\Scans\vlan30-$stamp.csv" -q
What the switches do:
-f:range <start> <end>— the IP Range feeder.-f:file <path>reads targets from a text file instead.-o <file>— export to this file; the extension picks the format, and-oimplies auto-start.-q— quit once the file is written. Without it the window stays open.-a— append instead of overwrite (the CSV header is skipped when appending).-s— start automatically; single-letter options can be grouped, e.g.-sq.
The fetchers and port list come from the GUI preferences you saved, so set them up once interactively before scheduling anything.
Clean the CSV in PowerShell
Depending on your display settings the file may still contain rows for hosts that never answered. Strip them and sort numerically by address:
$rows = Import-Csv "C:\Scans\vlan30-$stamp.csv"
$rows |
Where-Object { $_.Ping -and $_.Ping -notmatch '\[n/a\]|\[n/s\]' } |
Sort-Object { [version]$_.IP } |
Export-Csv "C:\Scans\vlan30-$stamp-alive.csv" -NoTypeInformation
The [version] cast is a cheap trick that sorts dotted quads correctly (10.20.30.9 before 10.20.30.10). To see what changed since last week, compare two runs on the IP and MAC columns:
Compare-Object (Import-Csv .\vlan30-last.csv) (Import-Csv .\vlan30-now.csv) -Property IP,'MAC Address'
A => row is new on the wire; <= means it disappeared.
Common mistakes
- Scanning across a router and trusting the MAC column. Off-segment, every MAC is the gateway’s or blank. Scan from inside the VLAN.
- Believing “dead” means “absent”. Default Windows firewall rules drop ICMP echo. A host that doesn’t ping may still be very much alive on 445 or 3389.
- Cranking threads on a thin link. Very high thread counts over a VPN or a small branch firewall produce false negatives and angry connection-table alarms. If results look patchy, lower the thread count and raise the timeout.
- Opening the CSV in Excel on a comma-decimal locale. Excel may cram every column into A. Use Data → From Text/CSV and set the delimiter, or stay in PowerShell.
- Forgetting the paperwork. A scheduled scan with no ticket reference looks exactly like reconnaissance to the next person who reads the firewall logs.
Where to go next
The full Angry IP Scanner review covers plugins, the licence and where it runs out of road. If you need share-level detail rather than a host list, read the Angry IP Scanner vs LizardSystems Network Scanner comparison, and for a Windows-only team the Angry IP Scanner vs Advanced IP Scanner page. Everything else in this space sits in LAN & Port Scanners.