Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] How to define 'custom' rtp tcp and udp ports in Wireshark?

From: "Frankel, Stewart" <Stewart_Frankel@xxxxxxxxx>
Date: Tue, 5 Jan 2010 10:38:20 -0500
Title: How to define 'custom' rtp tcp and udp ports in Wireshark?

Hello,

I have voip telephones that use several ranges of udp and tcp ports for communication.

I was wondering how to mark these ports as rtp and rtpc traffic.

Examples:
Some phones use ports 5004 thru 5068 udp for voip (not sip) and 5566/5570 tcp for rtpc
I know this overlaps 5060 but hopefully I can deal with this another way --

Some phones use ports 6004 thru 6098 udp and 68002 tcp for rtpc

Is there an easy way to tell Wireshark about these 'ranges' of ports and mark them as voip or rtp so I can collect and playback the audio and watch the control ports as rtpc or do they need to be added to the cfilter or some other file one at a time?

Thanks,
 
Stewart