Wireshark-users: Re: [Wireshark-users] Decode entire packet capture file.
From: Boaz Galil <boaz20@xxxxxxxxx>
Date: Tue, 20 Oct 2009 02:02:33 +0200

Guy,

Thanks for the fast comment. Option 2 did the trick. Can you please provide me some information on how can I detect SSRC changes using wireshark?

 



On Tue, Oct 20, 2009 at 1:53 AM, Guy Harris <guy@xxxxxxxxxxxx> wrote:

On Oct 19, 2009, at 4:45 PM, Boaz Galil wrote:
> 1.I have a packet capture that include many RTP streams. Is there a
> way for me to select all UDP packets in the file and to decode them
> as RTP stream?
>
No.

However, you can

       1) select a particular UDP packet and use "Decode As..." to have
Wireshark decode UDP traffic to and from one of the ports involved as
RTP, which you'd need to do once per RTP stream

or

       2) enable the "Try to decode RTP outside of conversations" option for
the RTP dissector and have Wireshark try to identify RTP packets
heuristically (note: it can't always get the right answer, so, with
that option set, it might think some packets that aren't RTP are RTP).
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
            mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe



--
Boaz.