有时候新接入的设备没有显示器, 无法查找设备的ip地址, 有两种方式查看
- 一种方式通过路由器上去查看
- 还有一种方式通过arp方式
通过arp -a
命令可以查找局域网内ip地址和mac地址的对应关系, 不过该列表是一个缓存列表, 需要进行过通信才可以显示出来. 所以可以通过ping命令缓存一遍网段内的ip地址
单线程, 慢
for var in {1..254};
ping -c 1 -w 1 -W 1 $ip >/dev/null 2>&1
if [ $? = 0 ];then
echo "$ip [yes]"
echo "$ip [no]"
echo "ping log:" > ./ping.txt
for i in {1..254}
ping -c 1 -w 1 -W 1 $iprange$i | grep -q "ttl=" && echo "$iprange$i [yes]" >> ./ping.txt || echo "$iprange$i [no]" >> ./ping.txt &
echo "wait 5s...."
sleep 5
cat ./ping.txt
cat ./ping.txt | wc -l
for /l %i in (1,1,255) do @ping -w 20 -n 1 192.168.0.%i | find /i "ttl"
参考 ip_scan
# Works Cited: Runspaces Simplified - https://blog.netnerds.net/2016/12/runspaces-simplified/
Scan an IP range and report how many IPs are alive.
Uses Multi Threading and only 1 ping to accomplish the task faster. (Inspired by Angry IP SCanner)
.PARAMETER <Parameter_Name>
In the top of the script, set your IP ranges. You can scan multiple ranges. Handy for corporate nets.
Text to Powershell Console
Version: 1.01
Author: Gordon Virasawmi
GitHub: https://github.com/GordonVi
Creation Date: 10/25/2019 @ 6:56pm
Purpose/Change: Initial script development
License: Free for all. Too simple to charge for. Too important to not publish.
# --------------------------------------------------
$threads = 1000 # how many simultanious threads. I've tested up to 1000 ok against ~3600 local IPs, ~900 active.
$list = for ($a=1; $a -le 255; $a++) # set the last octlet range
"10.0.0.$a" # set the first 3 octlets.
# --------------------------------------------------
write-host " Threads: " -nonewline -foregroundcolor yellow
" Build Pool: "
" Drain Pool: "
" ---------------------"
write-host " Total Hosts: $($list.count)"
write-host " Alive Hosts: "
write-host " Dead Hosts: "
# BLOCK 1: Create and open runspace pool, setup runspaces array with min and max threads
$pool = [RunspaceFactory]::CreateRunspacePool(1, $threads)
$pool.ApartmentState = "MTA"
$runspaces = $results = @()
# --------------------------------------------------
# BLOCK 2: Create reusable scriptblock. This is the workhorse of the runspace. Think of it as a function.
$scriptblock = {
Param (
$ping=$(Test-Connection -ComputerName $ip -Count 1).scope.isconnected
if ($ping -eq "true") {
#$mac=$($(arp -a $ip)[3]).Split(" ",[System.StringSplitOptions]::RemoveEmptyEntries)[1]
$mac=$(get-netneighbor -ipaddress $ip).LinkLayerAddress
} else {
# return whatever you want, or don't.
return [pscustomobject][ordered]@{
ip = $ip
ping = $ping
MAC = $mac
# --------------------------------------------------
# BLOCK 3: Create runspace and add to runspace pool
foreach ($ip in $list) {
$runspace = [PowerShell]::Create()
$null = $runspace.AddScript($scriptblock)
$null = $runspace.AddArgument($ip)
$runspace.RunspacePool = $pool
# BLOCK 4: Add runspace to runspaces collection and "start" it
# Asynchronously runs the commands of the PowerShell object pipeline
$runspaces += [PSCustomObject]@{ Pipe = $runspace; Status = $runspace.BeginInvoke() }
$Host.UI.RawUI.CursorPosition = New-Object System.Management.Automation.Host.Coordinates 16 , 2
write-host "$counter " -nonewline
# --------------------------------------------------
# BLOCK 5: Wait for runspaces to finish
do {
$Host.UI.RawUI.CursorPosition = New-Object System.Management.Automation.Host.Coordinates 5 , 9
$cnt = ($runspaces | Where {$_.Result.IsCompleted -ne $true}).Count
write-host "$cnt "
} while ($cnt -gt 0)
# --------------------------------------------------
# BLOCK 6: Clean up
foreach ($runspace in $runspaces ) {
# EndInvoke method retrieves the results of the asynchronous call
$results += $runspace.Pipe.EndInvoke($runspace.Status)
$Host.UI.RawUI.CursorPosition = New-Object System.Management.Automation.Host.Coordinates 16 , 3
write-host "$($total-$counter) " -nonewline
# --------------------------------------------------
# Bonus block 7
# Look at $results to see any errors or whatever was returned from the runspaces
# Use this to output to JSON. CSV works too since it's simple data.
# $results | convertto-json -depth 10 > ip_scan.json
$alive = $($results | ? {$_.ping -eq "true"}).count
$dead = $($results | ? {$_.ping -ne "true"}).count
$Host.UI.RawUI.CursorPosition = New-Object System.Management.Automation.Host.Coordinates 0 , 5
write-host " Total Hosts: " -nonewline -foregroundcolor cyan
write-host " Alive Hosts: " -nonewline -foregroundcolor green
write-host " Dead Hosts: " -nonewline -foregroundcolor red
$results | ? {$_.ping -eq "true"} | select ip,DNS,MAC
修改powershell权限, Set-ExecutionPolicy RemoteSigned
, 修改38行左右的ip地址, 然后.\ip_scan.ps1