# Layer 2 vs Layer 3 Scanning for Asset Discovery

Where you place a network scanner decides what it can find. A scanner that reaches the network through routers (Layer 3) sees only the hosts that answer at the IP layer and can never learn their hardware identity, while a scanner sitting directly on each segment (Layer 2), such as a multi-homed scanner with an interface in every VLAN, also finds the silent devices and fingerprints them by MAC address. That is the difference between a list of IP addresses and an asset inventory you can defend.

![The same network segment scanned two ways: a Layer-3 scan across routers sees only the hosts that answer at the IP layer and leaves silent or filtered devices unidentified, while a Layer-2-adjacent scan on the segment resolves every device with its hardware identity](layer2-visibility-comparison.png)

## What can a Layer 3 scan across routers see?

The most common set-up is one central scanner reaching the rest of the network through routers and firewalls, using ping sweeps and TCP/UDP port probes. It hits a hard ceiling:

- **It sees only what answers at the IP layer.** Hardened servers, embedded systems, medical and industrial equipment and security appliances often drop pings and filter ports. To a Layer 3 sweep they look like empty space.
- **Firewalls decide what it can reach.** Segmentation that correctly blocks traffic also blocks the scanner.
- **It can never learn a device's hardware identity.** A router rewrites the source MAC address on every packet it forwards, so a scanner on the far side physically cannot see a remote host's real MAC address. MAC addresses only mean something inside one broadcast domain.

The result is an inventory biased toward cooperative hosts, missing the silent and filtered devices that are often the riskiest.

## What does Layer 2 scanning add?

Put the scanner on the segment it scans, with no router in between, and a richer layer becomes visible:

- **ARP cannot be refused on the local segment.** The Address Resolution Protocol works only inside a broadcast domain, and any device that wants to talk on that segment must answer it. A host can silently drop your pings, but it still answers ARP.
- **MAC addresses identify the hardware.** The first half of a MAC address (the OUI) is assigned to a manufacturer, which tells you whether an unknown IP is a Cisco switch, a Siemens PLC, an Axis camera or a Raspberry Pi. You cannot get that identity from across a router.
- **It finds what Layer 3 misses:** hosts that block pings, devices with misconfigured or duplicate addresses, and rogue or unmanaged equipment.
- **Switch data adds topology.** CDP and LLDP neighbours and the ARP and MAC tables on switches and routers show which port and VLAN a device sits on.

Mainstream discovery engines work this way. Rapid7's documentation lists "ARP pings (for local network)" among its discovery methods; to check MAC addresses it "makes a direct ARP request to the target asset to pick up its MAC address" and "retrieves the ARP table from the router or switch controlling the segment", and the scan engine "must reside on the same segment as the systems being scanned" ([Rapid7](https://docs.rapid7.com/nexpose/configuring-asset-discovery/)). runZero says "Discovery works best when the Explorer sits on the network it scans, with no gateway devices such as firewalls or routers in between", and calls Layer 2 probes "the most effective" way to enumerate MAC addresses ([runZero](https://help.runzero.com/docs/playbooks/scanning-ot-networks/)).

## What is a multi-homed scanner?

To get Layer 2 visibility everywhere, the scanner needs a presence on every segment you care about. There are two valid patterns:

1. **A multi-homed scanner:** one machine with an interface in each VLAN, usually through 802.1Q trunking or, on a virtual machine, one virtual network card per VLAN. One box becomes Layer 2 adjacent to many segments at once.
2. **Distributed scanners:** a separate scanner inside each segment or security zone, grouped so scan jobs are spread across them.

Multi-homing means fewer devices to maintain, at the cost of concentrating access in one machine and adding routing complexity. A distributed fleet scales cleanly and keeps each scanner's reach small, at the cost of more endpoints to manage. Mature deployments often combine the two.

## What are the challenges of multi-homed scanning?

- **Routing gets complicated.** With several interfaces and one default gateway, a reply can leave by a different interface than the request arrived on. Linux reverse-path filtering then silently drops it, and several interfaces can confuse ARP. Plan source-based (policy) routing so each interface's replies leave the way they came.
- **The adjacency has to be engineered:** tagged switch ports and correctly configured tagged interfaces, or per-VLAN virtual network cards. It is a network design task.
- **OT and medical networks need care.** Some of these devices misbehave under active probes that an ordinary IT host would ignore. Default to passive discovery (listening to traffic) day to day, and keep active scans for planned maintenance windows or a device's pre-production testing, sending only well-formed traffic, phased one range at a time while you watch device health.
- **One interface per VLAN does not scale forever.** A single machine cannot hold an interface in hundreds of segments; beyond a point, distributed scanners are the right answer.
- **The scanner is a high-value target.** It bridges zones that are meant to be separate, so a compromised scanner undermines the very segmentation it inventories. Harden it, restrict who can reach it and log what it does.
- **Passive and active discovery complement each other.** Passive monitoring is safe and continuous but cannot see devices that are not transmitting; active scanning finds them but is more intrusive.

## Where does Layer 2 visibility matter most?

- **Operational technology (OT) and industrial control systems:** many devices cannot run an agent, networks are split into zones, and the encouraged practice is a scanner inside each zone, passive in normal operation.
- **Healthcare and IoT:** embedded and medical devices often ignore pings and cannot host an agent, so MAC fingerprinting from the segment is frequently the only practical way to identify them. A home EV charger on a business network is the same problem ([what we found in one](/blog/2026-05-22-ev-charger-iot-security)).
- **Shadow IT:** ARP-level discovery reveals devices that were never registered or were plugged in without approval.
- **Heavily segmented networks:** a local presence is the only way to inventory an isolated segment without punching holes in the controls that protect it.

## How do you get a complete asset inventory?

Complete visibility is the foundation of vulnerability management, segmentation, incident response and compliance, and it depends less on which scanner you buy than on where you place it. Put scanners Layer 2 adjacent to the segments they inventory, choose multi-homed, distributed or both deliberately, combine passive and active discovery, and treat the scanner as a sensitive asset. Discovery is also the weak left end of a longer curve, the argument in [Vulnerability Lifecycle: Why Tooling Is Not Enough](/blog/2026-08-14-procured-not-operated-vulnerability-lifecycle).

If you are not sure what your scanners can see, the [$399 IT Security Review](/security-review) is a fixed-price first look, or [contact us](/contact) to plan a discovery deployment.

## Sources

- runZero: [Scanning OT networks](https://help.runzero.com/docs/playbooks/scanning-ot-networks/), [Full-scale deployment plan](https://help.runzero.com/docs/deployment-plan/) and [Managing Explorers](https://help.runzero.com/docs/managing-explorers/)
- Rapid7: [Configuring asset discovery (Nexpose/InsightVM)](https://docs.rapid7.com/nexpose/configuring-asset-discovery/), [What is IT Asset Discovery?](https://www.rapid7.com/fundamentals/what-is-it-asset-discovery/) and [Different Approaches to Asset Discovery](https://www.rapid7.com/blog/post/2024/10/17/understanding-your-attack-surface-different-approaches-to-asset-discovery/)
- TechTarget: [How to use arp-scan to discover network hosts](https://www.techtarget.com/searchsecurity/tutorial/How-to-use-arp-scan-to-discover-network-hosts)
- O'Reilly, *Kali Linux Network Scanning Cookbook*: [Layer 2 discovery, ARP](https://www.oreilly.com/library/view/kali-linux-network/9781787287907/634f7a44-1cac-45fa-95fb-11eea0b4a5a6.xhtml)

*Educational and vendor-neutral: product documentation is cited as a factual reference on discovery mechanics, not as an endorsement.*

*Updated 4 October 2026: rewritten answer-first, and the Rapid7 and runZero quotes updated to their current documentation.*
