I decided to break a trace on three parts with filtering SIP, RTP and DIAMETER protocol. For SIP and DIAMETER it went ok - I filtered the original trace and saved it as a new (trace) file. When a new file was opened, it was displayed ok.
But now, when I filter the original file with RTP protocol, save it as a new file and then open this new file, instead of RTP it shows like I filtered with UDP protocol. Why? I don't want so...
asked 28 Apr '11, 16:43
Wireshark parses the SDP information in the SIP packets to learn about the upcoming RTP sessions. So, without the SIP packets, it does not know that the UDP packets are actually RTP packets. Possible solutions:
answered 28 Apr '11, 22:52