Does this help? It basically uses dumpcap (the capture engine) on the remote platform (your VoIP box) from the capture host. If you set it up so that the output from the SSH tunnel is put into a file, than that's your capture file. Or load it directly in Wireshark and save from there, if that suits your use case.