Sniffin’ the VOIP traffic

Source: asteriskblog.com

This time we will install a network protocol analyzer to watch the traffic on our LAN from initiating and connecting a SIP call.

The Wireshark open source project was formerly known as Ethereal. I used to work for a great company called Cybera as a programmer, and I was always fascinated by networking. I’d bug the network engineers for any information I could, and play around with Ethereal to try to understand what they were talking about.

If you’re working under windows, download the installer. For our Ubuntu or Debian friends, it’s available under the standard free apt archives.

There’s one little trick you need to be aware of during the install.

winpcap

Make sure you select WinPCAP as part of the installed goods.Complete the install and start the program. Minimize it for the time being.

Launch your VMWare server and the Trixbox instance, log in, and you’ll notice the IP address shown after you log in. Mine is 192.163.1.93.

Run over to another box on your LAN and make sure you can ping this address, as detailed in my last post.

If you don’t see ‘Logged In’ in the faux LCD window, most likely you’ll need to update the IP address that the phone needs for Asterisk.

Click the little Menu button juuuust to the left of the green phone button. Select System Settings->Sip Proxy->Default.

Menu

Make sure that the IP address for Domain/Realm, SIP Proxy, and Outbound proxy are all set to the IP address of the Asterisk Trixbox server you just started via VMWare.

Remeber, Nerd Vittles set us up with 500 and 501 as 2 extensions to use with these phones. Dial 501 from the 500 phone or vice versa. I launched mine just now and I can hear the kids, dog, and my wife doing fun stuff. Frankly at this point I have to sit back and marvel at the processes running to make this possible. It just blows my mind.
Now comes the hackin’ part. As the SIP call is in progress, flip back to Wireshark.

wiresharc-startup.PNG

From the main window, select Capture->Interfaces.

wriesharcints.PNG

I can see one of the listed network interfaces dealing with a lot of traffic. Choose that one and press the capture button.

wriesharkcaping.PNG

Let wireshark capture at least 5 or so seconds of traffic. So far, on mine, the vast majority of this VOIP traffic is of the UDP variety. Click Stop and wireshark will dump it all into its analysis window.

analyze.PNG

Every line that says OICQ Protocol represents one UDP (User Datagram Protocol) VOIP packet traversing the network. As a side note, it appears that Wireshark has made the assumption for us that these packets are really part of a chat protocol popular in China, which, of course, is not correct.

Right click on one, and select ‘Open in new window’. Go down to the bottom and look at the ‘data’ section of the packet. This data section represents the actual digitized voice of the VOIP call. It’s interesting to me that the protocol used is UDP, which is one of the two major types of IP packets, the other being TCP. UDP is a connectionless protocol, which means that the client generating the traffic simply puts the packet on the wire without regard to checking to see if the recipient actually received it. This also implies that the recipient has to collect the correct UDP packets and reorder them to form a meaningful conversation. I wonder what role the SIP ’stack’ in asterisk plays in this function. I suppose we’ll find out here at Asteriskblog!

Well, I hope you’ve found that illuminating, and I’m sure we’ll be referring to this tool to diagnose our further work in Asterisk. Please contact me if you have any questions.

Published on September 16th, 2006 under ,


Last 20 posts tagged "SIP"

Time For A SIP of 3G

Source: andyabramson.blogs.com

I’ve made 3G calls with SIP on my Nokia N and E series phones using both Truphone and Gizmo, but on my iPhone I’m hobbled just like everyone else who uses on (that’s not Jailbroken)…

Published on November 29th, 2008 under , , ,

Will SIP Make Calling Cards Obsolete?

Source: andyabramson.blogs.com

Michael Graves has a post today on how to save money when making calls to or from overseas. He highlights client Junction Networks and their OnSip service which I use quite a bit when I go across…

Published on November 23rd, 2008 under ,

SIP Trunking Saves Money

Source: www.voip-news.com

-news.comA new report from Light Reading’s VoIP Services Insider says that more network operators and enterprises are using SIP trunking as a way to lower expenses for IP networks.
“As enterprises…

Published on November 7th, 2008 under , , , ,

Friday Links: SIP Calling, Hacking, Resellers

Source: www.voip-news.com

-news.comAndy Abramson at VoIP Watch says that Fring makes SIP calling easy on Junction Network’s OnSip.
A new book shows it’s really easy to hack VoIP. Read about it on VoIP Monitor.
VoIP…

Published on November 1st, 2008 under , ,

Fring Makes SIP Calling Easy With OnSIP from Junction Networks

Source: andyabramson.blogs.com

Mike Oeth, the CEO and one of the founders of client Junction Networks shared some news with me recently. It was the kind of news that I liked to hear, because it showed that imagination was…

Published on October 29th, 2008 under , , , , ,

pbxnsip Chooses NEI

Source: www.voip-news.com

-news.comNEI will be deploying telephony appliances to support VoIP-based communications systems for pbxnsip.
“We chose NEI for its outstanding reputation and demonstrated experience in t…

Published on October 29th, 2008 under , ,

SIP Director Wins Award

Source: www.voip-news.com

-news.comRadware’s SIP Director has won a 2008 Internet Telephony Excellence Award from Internet Telephony magazine.
“Advancing IP communications and providing real solutions in the marketplac…

Published on October 21st, 2008 under ,

Budget Saver? WinSIP

Source: www.voip-news.com

-news.comTMCnet had an interesting article today on WINsip and how it could be a budget booster for companies feeling the budget crunch. It’s definitely one of those cases where you have to…

Published on October 21st, 2008 under , ,

NeuStar SIP-IX VoIP Trial A Success

Source: www.voip-news.com

-news.comNeuStar, Inc. has successfully trialed its SIP-IX VoIP Interconnection Exchange service. The company used four competitive local exchange providers for the trial.
“We’re glad to…

Published on October 7th, 2008 under , , , , , ,

Wednesday Links: GoIP, SIP, more

Source: www.voip-news.com

Oooh! Free! There is a free webinar on enterprise SIP security coming. You can read about it on TMCnet.
Mobile VoIP Review attempts to set the record straight on the German ruling about VoIP…

Published on September 10th, 2008 under , ,

Austria Mobilkom Launches SIP SoftPhone

Source: andyabramson.blogs.com

Xnet’s iSoftPhone is being used as part of a launch of a new service called A1 over IP, a new telephony offering coming from Mobilkom Austria.

Xnet has developed the new A1 iSoftPhone for t…

Published on August 29th, 2008 under , , , , , , ,

Eyebeam and OnSip

Source: andyabramson.blogs.com

This is an audio sample file of my using CounterPath’s Eyebeam on my recently restored to brand spankin’ new condition by the Apple store here in Orlando. I reinstalled Eyebeam and configured…

Published on July 19th, 2008 under , ,

Sipera Gets Upgraded SIP Security

Source: www.voip-news.com

Sipera System’s Sipera IPCS security appliances  now have advance security for SIP trunking. Sipera VIPER Engine also has upgraded security as well.
“Many enterprises today are embracing…

Published on June 24th, 2008 under , , , , , , ,

The Cable Voice Business Market Gets SIP

Source: andyabramson.blogs.com

Here come the big tanks.

Now that the cable guys have proven they can sell voice as well or better than the phone company they are turning their focus to the business market…

Published on June 17th, 2008 under , , , , , ,

CounterPath Rolls Out Web Conferencing That’s SIP Based

Source: andyabramson.blogs.com

I like the idea of CounterPath rolling out audio conferencing to drive more sales of their flagship softclient Bria and Eyebeam, but I question the timing of the implementation of CounterPath’s…

Published on June 12th, 2008 under , , , ,

Siphera’s New Partner Network Unveiled

Source: www.voip-news.com

Sipera System has unveiled Sipera Partner Network, which provides distributors, resellers and other partners to add VoIP and UC security to its implementations.
“As more enterprises deploy…

Published on June 11th, 2008 under , , ,

Skype To SIP is Already Here

Source: andyabramson.blogs.com

Over the weekend James Body of Truphone mentioned hearing something about a Skype To SIP gateway platform with Voxeo. Now PhoneBoy tips off the world.

All I know is the calls to the PSTN of…

Published on April 22nd, 2008 under , , ,

AT&T / Starbucks / Apple Combo Video - Log On. Sip. Buy.

Source: alanweinkrantz.typepad.com

This video illustrates the process of logging on to the AT&T WiFi network at Starbucks, logging on the browser, going to iTunes and seeing the slightly different user experience of buying…

Published on April 18th, 2008 under , , , , ,

April 2008 New Product Roundup

Source: blog.voipsupply.com

With industry shows Von and Voicecon recently concluding, a slew of manufacturers have released new products. Here are a few highlights:
Grandstream

Brookline, Mass.-based Grandstream Communications…

Polycom Releases New Software and Updates

Source: blog.voipsupply.com

We received some information from Polycom this week about some software updates and a new productivity application suite. These can definitely help all you Polycom lovers out there, and VoIP…

Published on April 4th, 2008 under , ,
Member of "Hype Media! Network"