Address Discovery Scanners · reads the wire
Address discovery scanners for checking the record against the wire
Before you hand out a static address, you want two answers that should match and often do not: what the register says about that address, and whether anything replies when you ask. A discovery scanner supplies the second answer. It walks a range — a /24 on the server VLAN, the printer subnet, a DHCP pool — and records which addresses respond, and to what: ICMP echo, an ARP request on the local segment, a TCP connection to a common port, a NetBIOS name query.
On this site a scanner earns its keep by how useful its output is to the record. A list of live addresses on screen is a start. A list with MAC addresses, resolved names and a timestamp, exported in a format your IPAM or spreadsheet can ingest, is what actually closes discrepancies. That is why this category mixes standalone scanners with IPAM products that scan their own subnets: both produce the “what answered” column, but one hands it to you and the other files it automatically.
The table is ordered by how directly a scanner’s results can be reconciled with a stored address plan, and by how little effort that takes for an admin working alone. Our methodology page explains the criteria in full.
6 address discovery scanners side by side
Ordered by how easily each tool’s findings flow back into an address register. Standalone scanners rank on export quality; IPAM products rank on how their built-in scans flag drift. LizardSystems sits last because it answers a narrower question (what each host shares) and has had no release since 2021. Tool names lead to our register entry for that product; the vendor link leaves for the publisher’s own site.
| Tool | Licence | Platforms | What it records well | Suits |
|---|---|---|---|---|
| ManageEngine OpUtilsManageEngine (Zoho Corp.) | Free edition + paid | Windows or Linux server; web console | IP address manager paired with a switch port mapper, so a live address leads to a physical port | Admins who need to trace an address to a switch port as well as record it |
| Angry IP ScannerAnton Keks | GPLv2 | Windows, macOS, Linux (Java; bundled in the Windows and macOS packages) | Pluggable fetchers (ping, hostname, MAC, ports, NetBIOS) with CSV, TXT, XML and IP-port list export | A quick, portable check of what actually answers in a range before you assign an address |
| phpIPAMphpIPAM project | GPLv3 | Self-hosted web app (PHP on Apache or nginx + MySQL/MariaDB) on Linux; Docker | Subnet tree with scheduled ping/scan agents that flag live hosts missing from the record | Small teams replacing an IP spreadsheet without buying a licence |
| SolarWinds IP Address ManagerSolarWinds | Commercial · trial | Windows Server 2012 R2–2025 with SQL Server; web console | Subnet scans plus Microsoft, ISC, Kea, Cisco and Infoblox DHCP/DNS integration, with conflict and scope alerts | Windows-centric shops with Microsoft DHCP/DNS that want alerts, not just a list |
| GestioIPGestioIP | GPLv3 | Self-hosted web app (Perl + Apache/mod_perl + MySQL/MariaDB) on Linux; Docker Compose | Discovery that fills the register from routing tables, SNMP, DNS and ping, plus DHCP lease import | Admins who want an open-source IPAM that populates itself from the network |
| LizardSystems Network ScannerLizardSystems | Free personal · paid business | Windows (vendor lists Windows 7 to 10, Server 2008 R2 to 2016) | Range scans that list NetBIOS, FTP and web shares with read/write access per user | Windows admins checking which hosts in a range answer and what they share |
TechScan365 compiled this table independently: we are none of the vendors listed, and no row was paid for. Licence and platform details were matched to each publisher’s website on the date in the byline.
How to choose
- Know which replies the scanner trusts
Windows Firewall blocks ICMP echo by default on many profiles, and plenty of printers and IoT devices ignore ping. On the local segment an ARP-based check sees them anyway; across a router you need TCP probes or the router’s ARP table. A scanner that only pings will call used addresses free.
- Capture MAC addresses where you can
The MAC is what turns “something answered at .22” into “the HP printer that moved from the second floor”. MACs are only visible from the same layer-2 segment, or via SNMP from the router or switch, so plan where the scan runs from.
- Prefer exports that match your record’s columns
CSV with address, MAC, hostname and last-seen time can be diffed against an IPAM export in a few lines of PowerShell or Python. Formats that only make sense on screen leave the reconciliation to your eyes.
- Schedule it, or it will not happen
A one-off sweep is a snapshot. The drift you care about — the undocumented static added last Tuesday — shows up in repeated scans. IPAM tools with scheduled scan agents do this for you; with a standalone scanner, put a recurring task in the calendar and keep every export.
- Scope it to your own address space
Enter ranges explicitly and keep them to subnets you administer or are authorized in writing to assess. Coordinate with whoever runs intrusion detection so a sweep is not mistaken for something worse, and avoid scanning across VPN links to partners without their agreement.
Silence is not the same as free
The most expensive mistake in this category is treating a non-responding address as available. A laptop in a bag, a server powered off for maintenance, a camera that drops ICMP and a DHCP reservation for a device that is simply asleep all look identical to a quick ping sweep. Before assigning an address, check it three ways: the register, a scan that includes ARP or TCP probes, and the DHCP server’s leases and reservations. Our guide on finding genuinely free addresses turns that into a repeatable routine.
Vendor pages: ManageEngine OpUtils manageengine.com · Angry IP Scanner angryip.org · phpIPAM phpipam.net · SolarWinds IP Address Manager solarwinds.com · GestioIP gestioip.net · LizardSystems Network Scanner lizardsystems.com
Questions we get about address discovery scanners
Why does the scan find fewer devices than the DHCP server lists?
Leases outlive the devices that took them. A phone that left the building an hour ago still holds its lease until expiry, and many clients ignore ping. Compare the scan with the ARP table on the gateway and the active lease list, and treat the union as the real picture.
Can I scan across routed subnets?
Yes for ICMP and TCP checks, no for ARP and MAC addresses, which do not cross a router. Either run the scanner from a host on each segment, or use a tool that pulls the ARP and forwarding tables from your layer-3 devices over SNMP.
How often should discovery run?
Daily for server and infrastructure subnets where an undocumented static causes outages, weekly for user and printer VLANs. What matters more than the interval is keeping the results, so that “first seen” and “last seen” dates exist when you need them.
Is a free scanner enough, or do I need IPAM?
A free scanner tells you what is live today. It does not remember what was there last month, who owns it or why it has a static address. If you already keep a disciplined register, a scanner plus an export routine may be enough; if the register is the problem, look at the IPAM category first.
Keep going
Other categories
- IPAM Software — holds the record
- Subnet Planning & Calculators — draws the plan
Disclosure: every vendor link here points directly at the publisher’s official site, and we are paid nothing when you use one. Details are in our affiliate disclosure.