Wireshark-users: Re: [Wireshark-users] Requesting command to decode UDP packet to RTP

From: Hugo van der Kooij <hugo.van.der.kooij@xxxxxxxxx>
Date: Fri, 7 Apr 2017 06:53:37 +0000
This message contains a digitally signed email which can be read by opening the attachment.

Hugo van der Kooij 
network engineer 

QSight IT 

T : +31 15 888 0 345

F : +31 15 888 0 445
E : hugo.van.der.kooij@xxxxxxxxx
I : http://www.qsight.nl

Arnhem - Delft - Veldhoven


--- Begin Message ---
From: Hugo van der Kooij <hugo.van.der.kooij@xxxxxxxxx>
Date: Fri, 7 Apr 2017 06:53:37 +0000
This is why Laura always pushes you to use profiles.
And frankly. I couldn't use wireshark without them.

Met vriendelijke groet / With kind regards,
Hugo

-----Oorspronkelijk bericht-----
Van: wireshark-users-bounces@xxxxxxxxxxxxx
[mailto:wireshark-users-bounces@xxxxxxxxxxxxx] Namens Guy Harris
Verzonden: Thursday, 6 April, 2017 22:23
Aan: Community support list for Wireshark <wireshark-users@xxxxxxxxxxxxx>
Onderwerp: Re: [Wireshark-users] Requesting command to decode UDP packet to
RTP

On Apr 6, 2017, at 1:04 PM, Jaap Keuter <jaap.keuter@xxxxxxxxx> wrote:

> ... but isn't it always the same story; "how to get UDP dissected as 
> RTP"? I can't remember the question being asked the other way around....

Enabling the heuristic solves two problems: "how to get UDP traffic that's
RTP traffic dissected as RTP" and "how to get UDP traffic that's *not* RTP
traffic *mis*dissected as RTP". :-)  It's a *very* weak heuristic, and could
get a lot of non-RTP traffic misdissected as RTP.

Therefore, you might not want to permanently turn the heuristic dissector on
- you might want to turn it on for some captures but leave it off for
others.
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    https://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://www.wireshark.org/mailman/options/wireshark-users
 
mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe

Attachment: smime.p7s
Description: S/MIME cryptographic signature


--- End Message ---