This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I'm using Version 1.12.4 of Wireshark (Win64) and am attempting to analyse RTP packets that are carrying an MPEG-2 transport stream.

What I'm finding is that any RTP packet that contains a "null" MPEG-2 transport stream packet (PID 0x1ff) is flagged as a NULL packet in the main Wireshark display.

The upshot of this appears to be that the RTP stream analyser ignores these NULL RTP packets which inevitably results in a "Wrong sequence number" entry in the analysis output as the packet sequence number is deemed to be non-contiguous.

This seems wrong to me. Null MPEG-2 transport stream packets are perfectly legal and to be expected in order to hit a particular fixed bit rate. The presence of them in the stream shouldn't result in an error being flagged in the analysis tool.

Or am I not understanding something correctly and Wireshark really is trying to tell me something useful?

Thanks in advance for any information offered.

asked 10 Apr '15, 04:22

IanB's gravatar image

IanB
6113
accept rate: 0%

edited 10 Apr '15, 04:24


Wireshark RTP analysis has no notion of profiles for the various transports. It basically only understands the transport of continues voice (G.711) and a bit of Comfort Noise and DTMF signalling. Since other profiles make use of similar methods they come out fairly well in these analysis, but certain details may cause problems, like you've seen.

Unfortunately it is a significant job to make a fault tolerant MitM RTP endpoint which can handle all profiles, which is what would have to be done in Wireshark, and so far this has not happened.

permanent link

answered 10 Apr '15, 08:07

Jaap's gravatar image

Jaap ♦
11.7k16101
accept rate: 14%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×238
×100
×1

question asked: 10 Apr '15, 04:22

question was seen: 6,755 times

last updated: 10 Apr '15, 08:07

p​o​w​e​r​e​d by O​S​Q​A