1 | initial version |
They have differences because they're different packets.
The packet in "Local site part 1" and "Local site part 2" is from UDP port 5060 to UDP port 5060.
The packet in "Remote site part 1" and "Remote site part 2" is from UDP port 5067 to UDP port 16301.
So this has nothing to do with tcpdump vs. Wireshark or WinPcap on Windows vs. libpcap on whatever UN*X you were running on. If they were supposed to be the same packets, perhaps the packets captured on the remote side had passed through some form of gateway equipment that had modified them.