Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: Re: [Wireshark-users] RTP, SIP and RTCP

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "hne" <haneugen@xxxxxxxx>
Date: Mon, 14 Dec 2009 12:20:56 +0100

Thanks for the hint. Unfortunately it didn't work out quit that way. When I use the Decode as feature, it decodes only all packets to / from the involved ports as SIP, but thats all, the only way to have RTP packets to be decoded seems to be to do this RTP recognition for every port beeing used for RTP.

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
From: jaap.keuter@xxxxxxxxx
To: haneugen@xxxxxxxx
Date: 14:59:03, 12.12.2009
Subject: Re: [Wireshark-users] RTP, SIP and RTCP
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~



>>Hi,
>> 
>> The trick would be to look for what you think is a SIP packet and then 
>> use the Decode as feature. Once it sees the SIP/SDP it will find the 
>> RTP/RTCP too.
>> 
>> Thanks,
>> Jaap
>> 
>> Send from my iPhone
>> 
>> On 12 dec 2009, at 12:16, "hne" <haneugen@xxxxxxxx> wrote:
>> 
>> > Hi,
>> >
>> > I have a stream of captured RTP, SIP and RTCP packets, is there a 
>> > way to to have wireshark to recognize them, I mean their content, 
>> > since it is only able to display the fields of the TCP and UDP 
>> > headers.
>> >
>> > Thanks in advance.
>> >
>> > Cheers,
>> > hne
>> >
>> > ___________________________________________________________________________
>> 
>> 
>> > Sent via: Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx 
>> > >
>> > Archives: http://www.wireshark.org/lists/wireshark-users
>> > Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
>> > mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe
>> ___________________________________________________________________________
>> Sent via: Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
>> Archives: http://www.wireshark.org/lists/wireshark-users
>> Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
>> mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe
>> 


  • Follow-Ups:
    • Re: [Wireshark-users] RTP, SIP and RTCP
      • From: Jaap Keuter
  • References:
    • Re: [Wireshark-users] RTP, SIP and RTCP
      • From: Jaap Keuter
  • Prev by Date: [Wireshark-users] Check out this photo on MyDailyFlog!
  • Next by Date: Re: [Wireshark-users] RTP, SIP and RTCP
  • Previous by thread: Re: [Wireshark-users] RTP, SIP and RTCP
  • Next by thread: Re: [Wireshark-users] RTP, SIP and RTCP
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation