Ask Your Question
0

Can I capture from an IP phone?

asked 2019-05-16 23:31:49 +0000

updated 2019-05-17 05:55:27 +0000

Jaap gravatar image

If I have a PC with Wireshark installed and that PC is connected to an IP phone, then the IP phone connects to a Cisco switch, am I supposed to see both voice and data traffic from the Wireshark capture?

edit retag flag offensive close merge delete

4 Answers

Sort by ยป oldest newest most voted
0

answered 2019-05-17 02:49:15 +0000

Hi,

Most likely no. You'll see the traffic for the PC NIC only.

You would need to capture traffic on the switch to see both voice and data.

Cheers,

JF

edit flag offensive delete link more
0

answered 2019-06-03 03:36:24 +0000

This is when it is good to have an old HUB ,not a switch laying around.

edit flag offensive delete link more
0

answered 2019-05-17 06:05:16 +0000

Jaap gravatar image

You are not supposed to see the voice traffic. What you actually plugin to on the IP phone is a three port switch, one uplink port to the Cisco switch, one port internal for the IP phone and one for the PC. So the voice traffic directed to the IP phone comes into the uplink port and then stays in the IP phone through the internal port. The other traffic (for your PC) goes out the second external port. When you want to see the voice traffic you need to capture on the uplink port. This usually means inserting another capture switch between the uplink port and the Cisco switch port, or a span port on the Cisco switch.

edit flag offensive delete link more

Comments

See the CaptureSetup/Ethernet page on the Wireshark Wiki for more information on capturing on switched networks.

Guy Harris gravatar imageGuy Harris ( 2019-05-30 20:44:10 +0000 )edit
0

answered 2019-05-30 19:48:57 +0000

From what I have tested, the best way to see both types of traffic, is to do a span/rspan session of a trunk port on the switch and send it to my wireshark pc. As all traffic has to traverse the trunk port on the access switch to go up to the core/distribution layer. So if voice and data separation is done correctly via different broadcast domains (vlans), you guys are right, I should not being seeing voice traffic from my pc as this pc sits on the data vlan and voice on another vlan.

edit flag offensive delete link more

Comments

The "V" in "VLAN" stands for "virtual"; ultimately, on an Ethernet network, a machine is plugged into a physical LAN, so, as long as the network adapter and adapter driver/networking stack can be put into a mode where raw Ethernet packets are delivered and provided to a capture application, VLANs don't matter.

Guy Harris gravatar imageGuy Harris ( 2019-05-30 20:37:22 +0000 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

Stats

Asked: 2019-05-16 23:31:49 +0000

Seen: 250 times

Last updated: Jun 03