当前位置:
文档之家› Wireshark抓包分析PPT学习课件
Wireshark抓包分析PPT学习课件
• H.245 OLC & OLC ACK
© Polycom, Inc. All rights reserved.
15
• H.460.18 (Signaling) • H.460.19 (Media)
© Polycom, Inc. All rights reserved.
16
云视频
© Polycom, Inc. All rights reserved.
• Captures which do not include call signaling will list RTP as UDP packets; H.245 as TCP packets only.
© Polycom, Inc. All rights reserved.
8
• 分析RTP Stream
9
• 分析TCP Stream
© Polycom, Inc. All rights reserved.
10Βιβλιοθήκη 云视频© Polycom, Inc. All rights reserved.
How to capture? Wireshark的安装 Wireshark的使用 How to read H.323 message? 网络设备对我们的影响 断线问题案例 ALG故障案例
7
• Important things first: Wireshark will not usually recognize any VoIP calls in a capture unless call signaling (H.225.0, H.245, SIP/SDP) is also included inthe capture.
2
• 交换机镜像(Mirror + Wireshark) • 设备本身抓包(下载后,使用Wireshark进行分析) • RPAD抓包的方法 • DMA抓包的方法
• RPD抓包的方法 • RMX抓包的方法
© Polycom, Inc. All rights reserved.
3
云视频
© Polycom, Inc. All rights reserved.
© Polycom, Inc. All rights reserved.
20
云视频
© Polycom, Inc. All rights reserved.
11
© Polycom, Inc. All rights reserved.
12
• H.225 Admission
© Polycom, Inc. All rights reserved.
13
• H.225 Connect
© Polycom, Inc. All rights reserved.
14
How to capture? Wireshark的安装 Wireshark的使用 How to read H.323 message? 网络设备对我们的影响 断线问题案例 ALG故障案例
4
• 注意以下界面,一定要安装WINCAP。
© Polycom, Inc. All rights reserved.
How to capture? Wireshark的安装 Wireshark的使用 How to read H.323 message? 网络设备对我们的影响 断线问题案例 ALG故障案例
17
• TCP layer issue • UDP layer issue • ALG
© Polycom, Inc. All rights reserved.
18
• TCP三次握手 • 发起断链
• 发起断链
© Polycom, Inc. All rights reserved.
19
• HDX systems transmit H.245 RoundTripDelayRequest every 30 seconds. • An H.323 system is not required to transmit H.245 RoundTripDelayRequest • It is mandatory that a system which received H.245 • RoundTripDelayRequest acknowledge the request with H.245 RoundTripDelayResponse • If HDX does not receive RoundTripDelayResponse, it will terminate the H.323 call
© Polycom, Inc. All rights reserved.
①Wireshark considers all out-of-order packets as being lost. ②Wireshark will NOT consider late-arriving packets as being lost if the packets are still captured in order, nomatter how late those packets arrive. ③Jitter calculations done by Wireshark should be ignored.
Carol.Zhao@
© Polycom, Inc. All rights reserved.
云视频
© Polycom, Inc. All rights reserved.
How to capture? Wireshark的安装 Wireshark的使用 How to read H.323 message? 网络设备对我们的影响 断线问题案例 ALG故障案例
5
云视频
© Polycom, Inc. All rights reserved.
How to capture? Wireshark的安装 Wireshark的使用 How to read H.323 message? 网络设备对我们的影响 断线问题案例 ALG故障案例
6
• Filter
© Polycom, Inc. All rights reserved.