Ask Your Question

Where is the fault in this SIP flow?

asked 2024-02-19 01:01:27 +0000

mskr gravatar image

updated 2024-02-19 01:01:51 +0000

I captured the flow of SIP packets between my router and the SIP registrar, to find out why my telephone is occasionally unable to make and receive calls.

I discovered, that the SIP registration is not renewed correctly at one point, shortly before the telephone is "dead".

However, I am unsure where the actual fault is located, because there seem to be multiple network actors involved.

  • There is the registrar named with IP address
  • There an IP address, which is the router if I am not mistaken.
  • There is an unknown actor, which sends a SIP OPTIONS request, the purpose of which is unclear to me in this context. However it could be a security mechanism somewhere in the network, as the request contains headers related to the Sipvicious software. The actor appears only once in the whole capture. However other IP addresses repeat the same request later in time.
  • There is an another unknown actor, which sends a wrong SIP REGISTER request and appears only once in the whole capture. It occured to me that since the highlighted SIP REGISTER request comes from outside to my router (which is not a registrar) the router should just ignore it and continue with its registrar. Is it safe to assume that there is a bug in the router that prevents that?

Wireshark Capture of SIP Flow with Sipvicious OPTIONS packet selected

Wireshark Capture of SIP Flow with faulty REGISTER packet selected

I am not experienced in this kind of analysis, but I read about how SIP is supposed to work, and would be happy to learn how to find the faulty actor in such a case. I hope this is a good place to ask.

edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted

answered 2024-02-19 10:45:44 +0000

hugo.vanderkooij gravatar image

Based on the screenshots the VOIP Provider disconnects the phone at 13:13:54 with the BYE message. And you sofphone is OK with that. But it occurs directly after another REGISTER action from you which is not expected at al.

All the OPTION packets after that are just the usual "Let's see if we can mess up and enter" packets that internet is full of.

So see why your (soft)phone is loosing the connection without a packet to show for it. The error is on your end based on the limited data available.

edit flag offensive delete link more


Thank you for clarifying. I will try to find out more. However it will be difficult, because I do not have control over the router, which is a Speedport Smart 3 by Deutsche Telekom.

mskr gravatar imagemskr ( 2024-02-19 12:11:11 +0000 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower


Asked: 2024-02-19 01:01:27 +0000

Seen: 118 times

Last updated: Feb 19