This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Some SIP request/response messages are missing for calls in a live traffic trace

0

Hi,

I have been trying to capture trace for SIP and RTP to my vendor for live traffic. The problem is, some SIP request/response messages are missing for particular calls. For example, for a particular successful call, I am getting only INVITE and ACK messages by filtering using sip.To contains or sip.From contains, sip.Call-ID, sip.Via filters. Result for all those filters are same. I have tried Call flow from Telephoney> VoIP Calls, same result.

Any help regarding this situation would be much appreciated.

asked 10 Apr '15, 23:15

Sentinel's gravatar image

Sentinel
6112
accept rate: 0%

can you provide a sample capture file? If so, please upload it to google drive, dropbox or cloudshark.org and post the link here.

(11 Apr '15, 05:43) Kurt Knochner ♦

Hi Kurt, The capture I am talking about is really large as it was live traffic trace. So I am facing difficulties uploading it.

Can you give me any clue regarding this missing message scenario,why this might be occuring ? As I am totally blank on this right now !

(12 Apr '15, 23:57) Sentinel

What is the packet rate? Perhaps you have packet drops on your capturing interface. What OS and version, which wireshark version?

If TCP are used perhaps reassembly fails, try frame contains.

(13 Apr '15, 01:42) Anders ♦