FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ekrishnan
Staff
Staff
Article Id 247261
Description This article explains the usage of Wireshark to help view or understand the VOIP flow.
Scope FortiGate.
Solution

Once the packet for VOIP is captured using the sniffer, a similar output as below will be get:

 

For example:

 

# diagnose sniffer packet any 'host x.x.x.x and port xyz'  6 0 l

 

Port is the port number used for VOIP traffic eg: 5060 or can also be any custom port.

 

ekrishnan_6-1677472748531.png

 

Next, select 'Telephony' tab on the menu bar and select VOIP calls:

 

ekrishnan_7-1677472864552.png

 

A new window opens as per below select a packet and then select 'Flow sequence':

 

ekrishnan_5-1677472462685.png

 

The Flow sequence of the VOIP packet traffic as per below:

 

ekrishnan_8-1677473099482.png

 

This is a useful tool that can help in understanding the SIP packet flow process.

 

Alternatively, FortiGate GUI can also be used to perform the packet capture as per below:

 

On versions 7.2.X and above.

 

ekrishnan_9-1677474474854.png

 

On versions below 7.2.x:

 

ekrishnan_10-1677474514472.png
Contributors