Link to home
Start Free TrialLog in
Avatar of Link
LinkFlag for United States of America

asked on

Wireshark Filter for SIP RTP stream

I have a SIP trace with about 7 active calls. I have identified a problem for one particular call and can see that the RTP streams that are setup for this call are using port 59290 to IP-address1 and 10476 to IP-address2.

I would like to make a display filter for each of these RTP packet streams but this is beyond my capability to figure out do quickly enough (or if it can be done at all).

Any suggestions? Here is the Wireshark display filter page for RTP
http://www.wireshark.org/docs/dfref/r/rtp.html
ASKER CERTIFIED SOLUTION
Avatar of José Méndez
José Méndez

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Link

ASKER

The filter I was using  "udp.port == 56789 || udp.port 10476" was not showing RTP packets in the version of wireshark I was using (1.8.0). After I upgraded wireshark to the latest version it  did work.