[SIPForum-discussion] Wireshark Display Filter

Zuñiga, Guillermo Guillermo.Zuniga at cwpanama.com
Wed Oct 16 00:25:06 UTC 2013

You can use in wireshar rtp.ssrc== with the hex value of the RTP.

Guillermo Zuniga
Especialista de Soporte Técnico
Gerencia de Soporte Técnico

Tel:    +507 263-6671
Cel:    +507 6670-0481
Fax:    +507 265-3295
Email:  Guillermo.Zuniga at cwpanama.com




[cid:image0a179e.JPG at 2f4b4874.40a2b4e8]<http://www.cwpanama.com>

[cid:image4fd12d.JPG at cea94b0d.4091ca9e]<http://bit.ly/MasMovil>

De: discussion-bounces at sipforum.org [mailto:discussion-bounces at sipforum.org] En nombre de Tim Garey
Enviado el: martes, 15 de octubre de 2013 10:28 a.m.
Para: discussion at sipforum.org
Asunto: [SIPForum-discussion] Wireshark Display Filter

I have a large pcap file with about 7 active calls.  I can see on one particular call there is a problem and
need  to find out when in the trace the RTP stream ends for this call. I have identified where it starts
and ports being used, but it seems nearly impossible to find where it ends as the source/dest addresses
are the same for all calls.

Is there a way to create a  Wireshark display filter to show only the RTP stream with port = 52560 to IP-address1.
This would help greatly in troubleshooting


El contenido de este correo es confidencial y puede ser objeto de acciones legales.  Es dirigido solo para el o los destinatarios(s) nombrados anteriormente. Si no es mencionado como destinatario, no debe leer, copiar, revelar, reenviar o utilizar el contenido de este mensaje. Si ha recibido este correo por error, por favor notifique al remitente y proceda a borrar el mensaje y archivos adjuntos sin conservar copias.

The information contained in this e-mail is confidential and may also be subject to legal privilege.  It is intended only for the recipient(s) named above.  If you are not named as a recipient, you must not read, copy, disclose, forward or otherwise use the information contained in this email.  If you have received this e-mail in error, please notify the sender immediately by reply e-mail and delete the message and any attachments without retaining any copies.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://sipforum.org/pipermail/discussion/attachments/20131015/94cd5c1c/attachment-0002.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image0a179e.JPG
Type: image/jpeg
Size: 10257 bytes
Desc: image0a179e.JPG
URL: <http://sipforum.org/pipermail/discussion/attachments/20131015/94cd5c1c/attachment-0004.jpe>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image4fd12d.JPG
Type: image/jpeg
Size: 26068 bytes
Desc: image4fd12d.JPG
URL: <http://sipforum.org/pipermail/discussion/attachments/20131015/94cd5c1c/attachment-0005.jpe>

More information about the discussion mailing list