Wireshark-users: Re: [Wireshark-users] Decoding SIP Publish Messages

From: Martin Visser <martinvisser99@xxxxxxxxx>
Date: Thu, 3 Jun 2010 07:29:04 +1000
I assume at least they are showing up as as transport layer protocol (UDP,TCP,or SCTP). If not, you have a lower level issue with the capture.

Otherwise, then try "Decode As" and select SIP. If your SIP packets are not on port 5060 then Wireshark might not be automatically recognising it.

Regards, Martin

MartinVisser99@xxxxxxxxx


On Thu, Jun 3, 2010 at 6:07 AM, Duncan, Lisa M (Lamanna) <lisa.duncan@xxxxxxxxx> wrote:
Good Afternoon,

 Is anyone aware of a dissector or external tool that will decode a SIP Publish message?  These messages are showing up as IP fragments when loading a capture file.

Thanks,

Lisa

This communication is the property of Qwest and may contain confidential or
privileged information. Unauthorized use of this communication is strictly
prohibited and may be unlawful.  If you have received this communication
in error, please immediately notify the sender by reply e-mail and destroy
all copies of the communication and any attachments.
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe