Wireshark-users: [Wireshark-users] about the Edit ->Preference->Protocols-> RSA key list in wires
Hi,
I'm using wireshark to capture VOIP traffic.
Previously, I did the capturing in the lab with two computers where the VOIP clients are installed and run, and I filled in:
9.42.125.197.,5061,D:\Program Files\Wireshark\stx3455b.pem
9.42.125.197 is the SIP server
wireshark works and can decode TLSV1 packets into RTP/SIP packets automatically.
now, I'm doing the capturing at home, using VPN
However, the TLSV1 can't be decoded into RTP/SIP packets this time.
I noticed that the TLSV1 packets source IP addresses is the VPN server IP, however, previously, the source IP addresses are either SIP server( 9.42.125.197) or the other client computer.
I replace 9.42.125.197 with the VPN server IP in the RSA key list, however, it doesn't work.
Does anybody have any idea on this problem?
Thank you!