[Wireshark-users] Has anyone here tried capturing VOIP traffic from a Linksys VOIP Router

2008-01-10 Thread ARAMBULO, Norman R.
Hi, has anyone here tried to capture a VOIP traffic from a Linksys VOIP Router, we tried using the wireshark but it seem it doesnt recognized the captured packet, wireshark can display the protocols used. Hope you can enlighten me. Thanks. -- The information in this electronic message

[Wireshark-users] Sorry

2007-03-11 Thread ARAMBULO, Norman R.
Ulf Lamping, Im sorry for sending email to the wireshark-dev. "Reality is merely an illusion, albeit a very persistent one." -- Albert Einstein Blank Bkgrd.gif De

[Wireshark-users] Help on H323 Port Filtering

2007-03-09 Thread ARAMBULO, Norman R.
Hi, Right now we are using tshark for capturing packets on our network and use it to translate, it seem theres a lot of packet loss. Is it possible to dissect or parse a captured packet for VOIP since some of its succeding packets were eventually lost, we have found some TPKT and Q.931 protocol

[Wireshark-users] Help of Dissecting or Parsing Packets

2007-03-09 Thread ARAMBULO, Norman R.
Hi anders, How do I attached the sample files? Can I put it on as wireshark verbose? Pls see below files. Thanks No. Time Source Destination Protocol Info 116498 2007-02-23 14:55:00.564621 84.138.215.62 192.168.2.1 TCP 13644 > 1718 [PSH, ACK] Seq=0 Ack=0 Win=64290 Len=558 Frame 116498 (612

[Wireshark-users] FW: [tcpdump-workers] Help on Ethernet Size

2007-03-06 Thread ARAMBULO, Norman R.
Mar 6, 2007, at 6:28 PM, ARAMBULO, Norman R. wrote: Thanks for the enlightenment that helps a lot... Another thing how can I parse a voip call (h323 family, SIP, IAX etc.) Is wireshark capable of doing it. Yes. Can somebody send me a source code for parsing voip call in C language.

Re: [Wireshark-users] [tcpdump-workers] Help on Ethernet Size

2007-03-06 Thread ARAMBULO, Norman R.
to be added to or removed from a mailing list; it is not for messages sent to the list itself) On Mar 6, 2007, at 5:36 PM, ARAMBULO, Norman R. wrote: > Is the ethernet size always equal to 14 bytes? The lowest-layer Ethernet header is always 14-bytes long - 6 bytes of destination address

[Wireshark-users] Help on Tshark

2007-02-13 Thread ARAMBULO, Norman R.
Hi, Right now we are using tshark in capturing packets, some SIP calls were not displayed properly like the data shows http & etc. Then we notice that some protocols know to ethereal were not displayed by wireshark. What could be the cause? "Reality is merely an illusion, albeit a

[Wireshark-users] Help on XML Error

2007-02-08 Thread ARAMBULO, Norman R.
Can somebody explain to me what error am I encoutering when using Tshark, below are the errors I got. Thanks * tshark: XMLStub: Unable to open module libxml2.so * tshark: Diameter: Using static dictionary! (Unable to use XML) "Reality is merely an illu

[Wireshark-users] Help on Filtering Parameters for h323 VOIP Calls

2007-02-01 Thread ARAMBULO, Norman R.
Hi, Is there someone out there who has tried filtering h323 voip calls and can you help me with it. Thanks and more power.. "Reality is merely an illusion, albeit a very persistent one."

[Wireshark-users] Filtering Parameters for h323 VOIP Calls

2007-02-01 Thread ARAMBULO, Norman R.
Hi, Is there someone out there who has tried filtering h323 voip calls and can you help me with it. Thanks and more power.. "Reality is merely an illusion, albeit a very persistent one."

Re: [Wireshark-users] Help on H323 VOIP calls

2007-01-31 Thread ARAMBULO, Norman R.
Hi Jaap, Well actually were using a Red Hat Linux and capturing packets using tshark, I dont know if tshark can do it on large files, we're trying to iliminate the GUI since it lags, so how can we filter h323 calls what are the filtering parameters. Thanks "Reality is merely an ill

[Wireshark-users] Help on H323 VOIP calls

2007-01-31 Thread ARAMBULO, Norman R.
Hi, Can tshark or wireshark show h323 VOIP calls. Were trying to filter h245 & h225 but we cant seem to find the callee and called number. Have you tried it. Thanks "Reality is merely an illusion, albeit a very persistent one."

Re: [Wireshark-users] Filtering a very large capture file

2007-01-28 Thread ARAMBULO, Norman R.
Hi Stu, So you have captured a large data of 16Gb, is it from a large network? What is the average xx Mb/sec Iam also using tcpdump and tshark to capture large files our network has an average traffic of 500Mb/sec so what specs are you using in capturing such large files. Thanks -Ori

Re: [Wireshark-users] Help on tcpdump or dumpcap

2007-01-18 Thread ARAMBULO, Norman R.
Thanks for the response, yup I know that wireshark or ethereal cant handle large amount of data, so does tcpdump and dumpcap capable of handling such data, can we use it to capture large amount of data, save it to multiple files for Tshark or Tethereal for post process. Pls advise and thanks

Re: [Wireshark-users] Help on tcpdump or dumpcap

2007-01-17 Thread ARAMBULO, Norman R.
Sebastien Tandel, Thanks for the info, yup we already tried it but it seems it doesnt work. What we are trying to do is capture packets and save it in another file where tshark or tethereal process it, we tried using tcpdump or dumpcap but it doesnt work, the network is relatively high about

[Wireshark-users] Help on Tethereal, tcpdump & Dumpcap in capturing data on a GigE Interface

2007-01-16 Thread ARAMBULO, Norman R.
Hi, Is there someone here who has tried using tcpdump or dumpcap in capturing packets on a GigE interface, we tried to run it but the system freezes. Is there a way we can use it to capture data. Below are the command we use in capturing data. BTW we are using Sun Solaris9 Sparc (blade 1000).

Re: [Wireshark-users] Help on Inquiry

2007-01-16 Thread ARAMBULO, Norman R.
Hi jeff, Thanks for the info, is there a way we can capture such traffic aside from wireshark, then we would dissect it in another box or like capture packets then save it in another file like multiple files before we dissect it. Thanks ARAMBULO, Norman R. wrote: Hi, Actualy we are

[Wireshark-users] Help on Inquiry

2007-01-15 Thread ARAMBULO, Norman R.
Hi, Actualy we are planning to use wireshark on a large network so we could further study IP Packtes. Can wireshark support our needs. Thanks and more power. "Reality is merely an illusion, albeit a very persistent one."

[Wireshark-users] Help on Solaris9 Shutdown Problem while Capturing Packets

2007-01-15 Thread ARAMBULO, Norman R.
Hi, Currently we have already installed the ethereal software for our Solaris9 Sparc, but the problem is the blade server shuts down. The scenaio is: 1. We captured sample packets using tethereal with xx bytes. 2. then after analyzing the data, we tried capturing specific no. of bytes i.e.

[Wireshark-users] Help on Protocols in frame

2007-01-09 Thread ARAMBULO, Norman R.
Hi gerald, Well, Im running it on a Solaris9 sparc. Can I use the wireshark instead, but I cant find a stable or an installer for Solaris9 Hope you can help me with this. Thanks "Reality is merely an illusion, albeit a very persistent one."

[Wireshark-users] Help on Protocols in frame

2007-01-09 Thread ARAMBULO, Norman R.
Hi, Im using ethereal for capturing IP packets and the platform we used is Linux Enterprise, when we try to display the decode like on the frame it shows the ff. My problem is when we load it in a Sun Solaris platform the Protocols in frame is not present. Can somebody help me with this? What