Ask Your Question
0

Src and Dst IP not correct in my single host multiple loopback cards env.

asked 2024-04-25 18:29:08 +0000

wangkevin1029 gravatar image

Hi, guys,

I have a single host vm system, in order to see apps communication in wireshark, I installed multiple lookback cards, and distributed apps on different IPs.

but in wireshark log, I noticed horizontal communication line not shown properly, in sip level traffic, I can see communication is between different IP, but in IP level, Src and Dst IP are always same, which causes horizontal communication line shrinked to a dot with 2 ports on one IP.

Kevin

edit retag flag offensive close merge delete

Comments

trying to upload a image, but don't have enough points yet.

Kevin

wangkevin1029 gravatar imagewangkevin1029 ( 2024-04-25 18:32:53 +0000 )edit

The convention is to place it on a public file share then update the question with a link to it.
And/or if possible, a capture file would provide more information than a screen shot does.

Chuckc gravatar imageChuckc ( 2024-04-25 19:46:17 +0000 )edit

Hi, Chuckc,

https://www.dropbox.com/scl/fi/m60ms8...

I uploaded the capture file to Dropbox and share the link, not sure if need to login dropbox to download the file.

I made some progress, I deleted loopback network cards, instead, I added network cards from VMware setting.

now, I can see RTP communication showing properly in ladder diagram, which has correct src, and dst IP ( vmware virtual network card), but for sip communication, still only showing same IP for src, and dst.

Kevin

wangkevin1029 gravatar imagewangkevin1029 ( 2024-04-26 14:02:05 +0000 )edit

Is there a local firewall blocking ports?
icmp and sip shows sip traffic being rejected.

Chuckc gravatar imageChuckc ( 2024-04-27 00:50:26 +0000 )edit

Chuckc,

but all sip calls work as expected, if there is any sip port blocked, it will impact sip communication.

besides, For RTP communication, I can see the correct vmware cards mac address, and Ip address showing properly as below, which caused RTP communication between two IPs to show properly between 2 IPs...

Ethernet II, Src: VMware_11:15:b7 (00:0c:29:11:15:b7), Dst: VMware_11:15:a3 (00:0c:29:11:15:a3)

but for sip communication,

Null/Loopback Family: IP (2)

Kevin

wangkevin1029 gravatar imagewangkevin1029 ( 2024-04-27 19:20:24 +0000 )edit

1 Answer

Sort by ยป oldest newest most voted
0

answered 2024-04-27 00:58:34 +0000

johnthacker gravatar image

You're referring to the Flow Graph when you say "horizontal communication line", correct? That is a known issue that probably can be resolved soon: https://gitlab.com/wireshark/wireshar...

edit flag offensive delete link more

Comments

johnthacker ,

thx for your info.

Our single host demo system OS is 2012 server, on which I can only install 4.0.X version.

not sure latest ver 4.2.4 support this feature.

Kevin

wangkevin1029 gravatar imagewangkevin1029 ( 2024-04-27 19:13:44 +0000 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

1 follower

Stats

Asked: 2024-04-25 18:29:08 +0000

Seen: 154 times

Last updated: Apr 27