In need of help, very desperate(SIP capturing)


#1

Hi All,
I’m running wireshark on 2 computers, filtering it to sip since the application im testing use the sip protocol.
On my windows 7 everything is working properly.
On windows xp, wireshark don’t display some of the packets but i know they get there since the application is doing what it should do after it gets it.(Notify packets xml/sip)
Does anyone know what may be the problem? i haven’t change anything in the wireshark prefferences and both of my computers run by the same settings.

Thanks in advance if somone can help


#2

Hello,

Same version of wireshark ?
Same plugins ?
Same capture filter ?
Same display filter ?

Did you try without any filter ?

Try to disable the sip protocol to see if the difference still appear.

If one computer send 2 packets,
it is possible that the other computer receive only 1 packet
containing the data of the 2 sent packets.

Olivier


#3

Thanks for your reply,

The answer to all of your 4 questions is yes. it is the same.
I also tried without any filter and still some packets are missing.
The amazing thing is the packets get there for sure, the is no question about. I just can’t see it.
Tried re-installing the wireshark and everything.
Could it be just an OS issue?
Do you know of a freeware tool which is similar to wireshark? im really desperate and it’s a really important issue to me.

Thanks for any help you can give i really appreciate it.


#4

Did you “Try to disable the sip protocol to see if the difference still appear.” ?

Could it be :
If one computer send 2 packets,
it is possible that the other computer receive only 1 packet
containing the data of the 2 sent packets.

Is there any packet dropped (see the status bar of wireshark) ?

Look at Microsoft Network Monitor 3.3

Olivier