Capturing handshake between a SIP handset & PBX
Hello,
First of all apologies for the basic question.
I'm trying to capture the handshake packets when a SIP handset registers with a PABX & i'm struggling.
I enter the PBX details inc usernames, passwords, etc into the SIP handset. Then i unplug the handset & start the Wireshark then plug it back in.
Once the handset has booted back up I stop the trace & use the display filter to look at the ip address of the PBX to hopefully find the acknowledgement between the PBX & SIP handset but nothing appears. The PBX confirms the handset is registered.
Any idea's?
Thanks. Lee.
You'll need to describe your capture set up. What is the network relationship between the PBX, the handset and the host on which you're performing the Wireshark capture?
So the PBX, SIP handset & PC are all on the same subnet.
Does this answer your question?
Thanks. Lee.
Not really, how are they connected, presumably there's some sort of switch involved?
Okay sorry, so the PBX is connected to a Netgear GS728TP switch. This switch is connected to a Zyxel 8 port switch where my SIP device & PC is connected to.
Have you considered your capture setup?