I found this on the wiki site and need a little further help
interpreting:
“Q: What is a good filter for just
capturing SIP and RTP packets?
port sip
should capture both TCP and UDP traffic to
and from that port (if one of those filters gets "parse error", try
using 5060 instead of sip). For SIP traffic to and from other ports, use that port
number rather than sip.
For RTP packets, you would have to
determine one of the port numbers that would be used, and specify that port
number.”
Here are my questions:
1. port sip is what I
need to type into the filter space to get SIP traffic right?
2. It says I have to determine one of the port numbers for RTP, it uses
several port numbers, will just specifying one of them pick up the rest of the
RTP traffic?
3. So now what is the full syntax that I would type in the filter box to
answer: “What is a good filter for just capturing SIP and RTP packets?”
Thanks
Andrena Lefdahl
Technical Consultant
Eide Bailly Technology
Consulting
401 N. 31st Street,
Suite 1120
Billings, MT 59103
Work 406.867.4168
Cell 406.208.5342
Fax 406.252.8600
www.eidebailly.com/technology
PEOPLE. PRINCIPLES. POSSIBILITIES.