1 | initial version |
If the packets are PPPoE encapsulated, you need to use the filter pppoes and port 5060
. This is because the BPF filter engine needs to look at other offset locations for the port numbers, due to the PPPoE headers.
Hope this helps, if not, could you post the hex data of one packet that was captured without capture filter?