Scan 365 Pronetwork troubleshooting, reviewed

Guide · Angry IP Scanner

Check which hosts came back after a power or switch outage

Snapshot your authorised subnets before a maintenance window, rescan after the power or switch outage, and diff the lists to find hosts that stayed down.

The UPS gave out at 02:10, or a core switch rebooted into a config it shouldn’t have, and now the lights are back on. The first question from everyone is “is everything up?”, and the honest answer is “I don’t know yet”. Monitoring covers the servers you remembered to add; it rarely covers the badge readers, the label printers, the IP phones in the warehouse and the one PC under a desk running the scale software. A before/after sweep of your own subnets closes that gap in a few minutes.

This guide uses Angry IP Scanner, a free, GPL-licensed, Java-based scanner for Windows, macOS and Linux, and shows a Windows-only alternative. Scan only networks you are responsible for or have written authorisation to scan; even a ping sweep can trip IDS alerts, so tell the security team first.

Step 1: Take a baseline before you need it

The diff is only as good as the “before” list. Ideally you have one from before the outage; if the outage was unplanned, use the most recent export you have, the DHCP lease table, or an asset inventory.

  1. Open Angry IP Scanner and enter the range, for example 10.0.10.1 to 10.0.10.254.
  2. In Tools → Fetchers, keep Ping, Hostname and add MAC Address (works on the local segment) and a few ports that matter to you.
  3. In Preferences → Ports, list ports that prove a service is really up, not just the NIC: 22,80,443,445,3389,9100 covers SSH, web UIs, SMB, RDP and printers.
  4. In Preferences, on the scanning tab, choose the pinging method. Plain ICMP is fine for most LANs; if Windows Firewall on clients drops echo requests, a TCP-based pinging method or the port fetcher gives you a second signal.
  5. Scan, then Scan → Export all to CSV.

For scheduled baselines, Angry IP Scanner can run from the command line. The general shape is [options] <feeder> <exporter>:

# scan a range, export to CSV, and quit when done
ipscan -f:range 10.0.10.1 10.0.10.254 -o before-10.0.10.csv -q

-o starts the scan automatically and the file extension picks the export format; -q exits after exporting; -a appends instead of overwriting. The executable name and path differ between the Windows, macOS and Linux packages, so check the exact usage text under Help → Command-line usage.

Step 2: Rescan after power is restored

Wait until switches and DHCP are genuinely up — scanning while spanning tree is still converging just produces a list of false negatives. A reasonable sequence:

  1. Confirm the core and access switches are forwarding (uplink LEDs, management interface reachable).
  2. Confirm the DHCP server and DNS are responding.
  3. Give endpoints a few minutes to boot; many printers and phones take longer than PCs.
  4. Run the same scan with the same settings and export after-10.0.10.csv.

Step 3: Diff the two lists

Angry IP Scanner’s display option “Alive hosts (responding to pings) only” helps visually, but a proper diff is faster on anything larger than a /26. On Windows, PowerShell does it in a few lines:

$before = Import-Csv .\before-10.0.10.csv
$after  = Import-Csv .\after-10.0.10.csv

$aliveBefore = $before | Where-Object { $_.Ping -ne '[n/a]' -and $_.Ping -ne '[n/s]' } | Select-Object -ExpandProperty IP
$aliveAfter  = $after  | Where-Object { $_.Ping -ne '[n/a]' -and $_.Ping -ne '[n/s]' } | Select-Object -ExpandProperty IP

Compare-Object $aliveBefore $aliveAfter |
  Where-Object SideIndicator -eq '<=' |
  Select-Object @{n='StillDown';e={$_.InputObject}}

Column headers and the “no value” markers can vary with version and language, so open one export in a text editor and adjust the column names before relying on the script. On Linux or macOS, comm -23 on two sorted lists of alive IPs does the same job.

Step 4: Triage what’s missing

For each address in the “still down” list, work from the cheapest check upward:

  1. Look it up. Hostname from the baseline, DHCP reservation, or asset record tells you what it is and where it lives.
  2. Check the switch port. No link means power, PoE budget, or a cable. PoE is the classic post-outage failure: a switch that boots with a lower power budget may not power every phone and camera.
  3. Check the IP. A device with link but a different address came back on DHCP when it used to have a reservation, or fell back to a self-assigned address because DHCP was late.
  4. Check the service. A host that answers ping but not its service port (443 on a web UI, 9100 on a printer) is up but not healthy.

A Windows-only alternative

If you want a Windows tool that also lists shared folders and HTTP/FTP services for each host, LizardSystems Network Scanner checks online state by ping or by ports you specify and exports to HTML, TXT or XML. It’s free for personal use with a per-machine business licence; the review covers the details, including that the last release dates from 2021.

Common mistakes

  • No baseline. Without a “before”, you only know what’s up, not what’s missing. Schedule a weekly export.
  • Ping-only checks. Windows clients often drop ICMP by default; a host can be up and invisible. Add a TCP port or two.
  • Scanning too early. Spanning tree, LACP and DHCP take time. False “down” results waste the first hour.
  • Different settings before and after. Change the fetchers or ports between runs and the diff is meaningless.
  • Scanning across a firewall or VPN from the wrong side. Rate limits and ICMP filtering on the path make healthy hosts look down; scan from inside each segment when possible.
  • Scanning networks you don’t own. Guest VLANs belonging to a landlord or a tenant’s segment are not yours to sweep.

The Angry IP Scanner review covers fetchers, performance and platform quirks. Other reachability tools are collected under Host & Connection Checks. If a host is up but slow after the outage, follow up with finding where packet loss starts. Get any scanner only from the project or vendor site — see where to get tools safely.

Tool used in this guide