From owner-freebsd-questions@FreeBSD.ORG Tue Jan 25 09:05:48 2011 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id AD5E5106566B for ; Tue, 25 Jan 2011 09:05:48 +0000 (UTC) (envelope-from bferrell@baywinds.org) Received: from baywinds.org (dsl092-017-098.sfo1.dsl.speakeasy.net [66.92.17.98]) by mx1.freebsd.org (Postfix) with ESMTP id 5DF548FC1E for ; Tue, 25 Jan 2011 09:05:47 +0000 (UTC) Received: from [66.92.17.195] (rr-iii [66.92.17.195]) by baywinds.org (8.13.6/8.13.6/SuSE Linux 0.8) with ESMTP id p0P8k2h7000428 for ; Tue, 25 Jan 2011 00:46:04 -0800 Message-ID: <4D3E8DCA.1020304@baywinds.org> Date: Tue, 25 Jan 2011 00:46:02 -0800 From: Bruce Ferrell User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.1.16) Gecko/20101125 SUSE/3.0.11 Lightning/1.0b1 Thunderbird/3.0.11 MIME-Version: 1.0 To: freebsd-questions@freebsd.org References: <4D3E782F.5040203@herveybayaustralia.com.au> In-Reply-To: <4D3E782F.5040203@herveybayaustralia.com.au> Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Subject: Re: Tracing packets - asterisk issues X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 25 Jan 2011 09:05:48 -0000 On 01/24/2011 11:13 PM, Da Rock wrote: > I have been trying to get some pointers on my asterisk issues and I've > only been hearing crickets chirping (Asterisk list and here). I need a > pointer or two so I can fix this issue, so I'll try another angle. > > How do I trace IP packets across the network (pf firewall included)? > And would it be possible to read it visually (human readable)? > > Cheers Use tcpdump to do a capture file. something like this: tcpdump -i eth0 -n -s 1500 -w sip.cap then feed sip.cap to wireshark filter for SIP and observe the SIP conversation It's also possible to decode the RTP stream