Wireshark

  • Riverbed Technology
  • WinPcap
the world's foremost network protocol analyzer
  • Wireshark
    • About
    • Download
    • Blog
  • Get Help
    • Ask a Question
    • FAQs
    • Documentation
    • Mailing Lists
    • Online Tools
    • Wiki
    • Bug Tracker
  • Develop
    • Get Involved
    • Developer's Guide
    • Browse the Code
    • Latest Builds

Wireshark-users: [Wireshark-users] VoIP calls GRAPH button gone. FLOW button shows SIP but not RTP or T.38

Date Index Thread Index Other Months All Mailing Lists
Date Prev Date Next Thread Prev Thread Next


From: "COHEN, HARVEY S (ATTLABS)" <hc2182@xxxxxxx>
Date: Tue, 31 Aug 2010 15:59:47 -0400

I just installed Wireshark 1.4 on WinXP. Under Telephony, VoIP Calls, the GRAPH button has been replaced by a FLOW button. The ladder diagram produced by the FLOW button includes the SIP and RTP, but not the T.38. How can I make the ladder diagram display the T.38 as in previous releases of Wireshark?

This sample has 352 T.38 packets, comprising an entire fax call:

|Time     | 12.40.234.2                           |

|         |                   | 12.20.15.34       |                  

|0.000    |         INVITE SDP ( g729 g711U telephone-event X-nt-i...req)          |SIP From: "BCM450 FAX"<sip:anonymous@xxxxxxxxxxx To:<sip:17322759486@xxxxxxxxxxx

|         |(5060)   ------------------>  (5060)   |

|0.050    |         100 Trying|                   |SIP Status

|         |(5060)   <------------------  (5060)   |

|2.041    |         180 Ringing SDP ( g729 telephone-event)          |SIP Status

|         |(5060)   <------------------  (5060)   |

|2.041    |         RTP (g729)                    |RTP Num packets:507  Duration:23.360s SSRC:0xD5D81350

|         |(28000)  <------------------  (16604)  |

|2.092    |         RTP (g729)                    |RTP Num packets:168  Duration:8.499s SSRC:0x4A0BC4D1

|         |(28000)  ------------------>  (16604)  |

|10.607   |         200 OK SDP ( g729 telephone-event)          |SIP Status

|         |(5060)   <------------------  (5060)   |

|10.611   |         RTP (g729)                    |RTP Num packets:308  Duration:11.799s SSRC:0x4A0BC4D1

|         |(28000)  ------------------>  (16604)  |

|10.619   |         ACK       |                   |SIP Request

|         |(5060)   ------------------>  (5060)   |

|25.352   |         INVITE SDP ( t38)             |SIP Request

|         |(5060)   <------------------  (5060)   |

|25.362   |         100 Trying|                   |SIP Status

|         |(5060)   ------------------>  (5060)   |

|25.403   |         200 OK SDP ( t38)             |SIP Status

|         |(5060)   ------------------>  (5060)   |

|25.470   |         ACK       |                   |SIP Request

|         |(5060)   <------------------  (5060)   |

|47.896   |         BYE       |                   |SIP Request

|         |(5060)   ------------------>  (5060)   |

|47.943   |         200 Ok    |                   |SIP Status

|         |(5060)   <------------------  (5060)   |

 

Harvey S. Cohen

AT&T Labs, Middletown, NJ

Mobile +1-908-768-5833

Office +1-732-420-4099

 

  • Prev by Date: Re: [Wireshark-users] Wireshark 1.4.0 is now available
  • Next by Date: [Wireshark-users] malformed packet
  • Previous by thread: Re: [Wireshark-users] Wireshark 1.4.0 is now available
  • Next by thread: [Wireshark-users] malformed packet
  • Index(es):
    • Date
    • Thread

Wireshark and the "fin" logo are registered trademarks of the Wireshark Foundation