<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Incomplete Pcap - RTP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete-pcap-rtp/m-p/332458#M84050</link>
    <description>&lt;P&gt;We are performing a pcap on our Firewall. We are capturing all traffic between two different Cidr's.&lt;BR /&gt;We see all of the sip information. We see full bi-directional traffic. We then see 2 RTP packets for each call then nothing else in the capture. The packets are not dropping,&amp;nbsp;We know RTP is indeed making it because there is no problem with the audio on the other side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why is it not capturing all RTP?&amp;nbsp; In wireshark if you do telephony -&amp;gt; voip calls all the ladders are right. we have everything we would expect from SIP/SDP and then we have 2 rtp packets and no other RTP. this is the same on a Transmit, Recieve, Firewall capture. If you do a rtp-&amp;gt;view streams you only see 2 packets per stream and there are hundreds of successful calls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does a PA only sample rtp on the plane that a pcap is performed at and fast tracks it? can someone explain this behavior?&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jun 2020 00:27:39 GMT</pubDate>
    <dc:creator>jon.swick</dc:creator>
    <dc:date>2020-06-09T00:27:39Z</dc:date>
    <item>
      <title>Incomplete Pcap - RTP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete-pcap-rtp/m-p/332458#M84050</link>
      <description>&lt;P&gt;We are performing a pcap on our Firewall. We are capturing all traffic between two different Cidr's.&lt;BR /&gt;We see all of the sip information. We see full bi-directional traffic. We then see 2 RTP packets for each call then nothing else in the capture. The packets are not dropping,&amp;nbsp;We know RTP is indeed making it because there is no problem with the audio on the other side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why is it not capturing all RTP?&amp;nbsp; In wireshark if you do telephony -&amp;gt; voip calls all the ladders are right. we have everything we would expect from SIP/SDP and then we have 2 rtp packets and no other RTP. this is the same on a Transmit, Recieve, Firewall capture. If you do a rtp-&amp;gt;view streams you only see 2 packets per stream and there are hundreds of successful calls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does a PA only sample rtp on the plane that a pcap is performed at and fast tracks it? can someone explain this behavior?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 00:27:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete-pcap-rtp/m-p/332458#M84050</guid>
      <dc:creator>jon.swick</dc:creator>
      <dc:date>2020-06-09T00:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: Incomplete Pcap - RTP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/incomplete-pcap-rtp/m-p/332762#M84106</link>
      <description>&lt;P&gt;did you disable hardware offloading? once a session is offloaded, you can no longer capture it (as captures happen in the dataplane, which is bypassed with offloading)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 09:55:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/incomplete-pcap-rtp/m-p/332762#M84106</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2020-06-10T09:55:40Z</dc:date>
    </item>
  </channel>
</rss>

