Wireshark-dev: [Wireshark-dev] Help on H323 Port Filtering

From: "ARAMBULO, Norman R." <NRARAMBULO@xxxxxxxxxxx>
Date: Fri, 9 Mar 2007 17:36:32 +0800
Hi,
 
Right now we are using tshark for capturing packets on our network and use it to translate, it seem theres a lot of packet loss.
Is it possible to dissect or parse a captured packet for VOIP since some of its succeding packets were eventually lost, we
have found some TPKT and Q.931 protocol and some are tcp ack. Another thing is, we tried filtering by port number and found
out that port 1718, 1719, 1720 both udp and tcp were tag as either h323hostcall or h323gateway by wireshark, are the packets
we captured are h323 voip calls? and can we dissect the data part which wireshark shows as data? Thanks and more power

  



 "Reality is merely an illusion, albeit a very persistent one."

                                                                                                                -- Albert Einstein