Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: [Wireshark-users] about the Edit ->Preference->Protocols-> RSA key list in wires

From: nangergong <nangergong@xxxxxxxxx>
Date: Mon, 31 Jan 2011 12:46:30 +0000
Hi,
 
  I'm using wireshark to capture VOIP traffic.
  Previously, I did the capturing in the lab with two computers where the VOIP clients are installed and run, and I filled in:

  9.42.125.197.,5061,D:\Program Files\Wireshark\stx3455b.pem

   9.42.125.197 is the SIP server
 
  wireshark works and can decode TLSV1 packets into RTP/SIP packets automatically.

  now, I'm doing the capturing at home, using VPN

  However, the TLSV1 can't be decoded into RTP/SIP packets this time.

  I noticed that the TLSV1 packets source IP addresses is the VPN server IP, however, previously, the source IP addresses are either SIP server( 9.42.125.197) or the other client computer.

  I replace 9.42.125.197 with the VPN server IP in the RSA key list, however, it doesn't work.

  Does anybody have any idea on this problem?

  Thank you!