Wireshark map/resolve ip & ports combination to different service names

asked 2021-05-16 17:45:58 +0000

prizzly gravatar image

I have a sip application server which have multiple service having same IP but different ports. Is it possible in wireshark to some how map/resolve ip & ports combination to different services names?

edit retag flag offensive close merge delete


Where would the "service name" be displayed or how would it be used?

Chuckc gravatar imageChuckc ( 2021-05-16 18:30:02 +0000 )edit

A sip server is having multiple logical application servers. All these logical application servers have same IP address but different ports. During a call traffic flows from logical server 1 with port 5060 then goes out to another sip server which then sends call towards logical server 2 with port 5070.

prizzly gravatar imageprizzly ( 2021-05-16 18:40:34 +0000 )edit

You can set coloring rules for conversations but that would only be available in the packet list.
Did you want "service name" to be displayed in the Packet Details or searchable with a Display Filter?

Chuckc gravatar imageChuckc ( 2021-05-16 18:45:44 +0000 )edit

Problem is I am not able to identify (unless I remember all ports used by different logical servers) which logical server is being used by checking the pcap trace. Currently I am using host file to resolve ip address but as host file can't have port details it becomes difficult to troubleshoot issues in the network.

prizzly gravatar imageprizzly ( 2021-05-16 18:54:18 +0000 )edit

The documentation could be a little clearer. You can have a services file per profile.
Would mapping the port number to a service name help?
It would require maintaining and switching to a profile based on which server the pcap is for.

Chuckc gravatar imageChuckc ( 2021-05-16 19:11:43 +0000 )edit