Ask Your Question
0

Wireshark does not find existing RTP stream

asked 2021-04-23 09:58:05 +0000

lsmod gravatar image

updated 2021-04-23 10:08:43 +0000

This question has already been asked 2011, but the answer does not fit any more to newer versions of Wireshark. https://osqa-ask.wireshark.org/questi...

The problem still exists now.

An RTP stream seems only been found when it is complete captchered. When the captchering begins after the stream has been established, Wireshark seems not to find it.

Why?

The option "Try to decode RTP outside of conversations" does not exist any more in Wireshark Version 2.6.20

What must be done to find an RTP stream that definitely exists?

Thanks for any hint.

edit retag flag offensive close merge delete

Comments

Have you tried 3.4.x in this regard? 2.6 is ..... rather old.

hugo.vanderkooij gravatar imagehugo.vanderkooij ( 2021-04-23 11:13:37 +0000 )edit

No, because this Wireshark is part of Debian 10 (stable).

Maybe there are newer packages, but not in buster-backports.

Then Debian 11 is needed - there it is wireshark_3.4.4-1_amd64.deb

lsmod gravatar imagelsmod ( 2021-04-23 11:18:05 +0000 )edit

2.6.x was EOL in October 2020. Any changes etc. would have to come from the distribution maintainers, i.e. Debian. See the Wireshark LifeCycle page for more info.

You can build your own copy of a supported version.

grahamb gravatar imagegrahamb ( 2021-04-23 12:06:21 +0000 )edit

Thank you, but this is not really an answer to the question.

Normally a newer version cannot be compiled under Debian 10, because the version of the dependent libraries are to old. So a complete new distribution of Debian must be installed to use one application, only for the hope that a special problem is fixed.

lsmod gravatar imagelsmod ( 2021-04-23 12:10:29 +0000 )edit

I agree that my comment doesn't answer the question, just pointing that your options are limited if you can't move to a supported version.

You could try your capture with a supported version to see if the issue has been fixed, or share your capture here for others to check for you.

grahamb gravatar imagegrahamb ( 2021-04-23 12:38:23 +0000 )edit

Another solution would be to try a distribution like Kali Linux that can be booted from a stick or in a virtual machine.

But i see that Kali Linux use Wireshark 2.6.4 https://tools.kali.org/information-ga...

lsmod gravatar imagelsmod ( 2021-04-24 07:06:10 +0000 )edit

1 Answer

Sort by ยป oldest newest most voted
0

answered 2021-04-23 13:01:06 +0000

Jaap gravatar image

Go to menu Analyze, select Enabled Protocols. Search for RTP. Tick 'rtp_udp'.

edit flag offensive delete link more

Comments

Yes - that's it - Thank You!

So this option has not gone - it has moved with another denotation.

lsmod gravatar imagelsmod ( 2021-04-24 07:07:42 +0000 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower

Stats

Asked: 2021-04-23 09:58:05 +0000

Seen: 1,458 times

Last updated: Apr 23 '21