Different versions of SIP packets on local and remote site?
I’m facing a problem with SIP protocol, which required capturing packets from local site with WireShark and remote site with TCPDUMP. When I analyze packages and specifically Register message, I notice Contact Header differs, in local capture Contact Header figure with a character "*" and remote Contact headers it appears with a double character of "@". Both files are open with same Wireshark version. Wireshark winpcap 4.1.2 version. Can't not figure what's going on.
Could you make both the local and remote capture files available, so we can look at them to try to figure out the reason for the difference?
Have you tried with a current version of Wireshark?
Can you add version information from
wireshark -v
or Help->About WiresharkIs it possible to share the capture files (or small section with the packets of interest)?
What sort of network devices are in between the local and remote site? Could they be modifying the SIP message?
Sorry I couldn’t find how to reply to each and make with add a comment, is not like other forums
Answer
Unfortunately I can’t, because there is information about a SIP account access and thus is one of the most hacks on the networks. When I make the post I tried to attach screen shot but forum setting is not allowing because it demands rank level.
(more)Sorry I couldn’t find how to reply to each and make with add a comment, is not like other forums
Answer
Unfortunately I can’t, because there is information about a SIP account access and thus is one of the most hacks on the networks. When I make the post I tried to attach screen shot but forum setting is not allowing because it demands rank level.