State of knowledge

March 2021

For the analysis, a recording file for the network analysis in connection with the UCServer may be necessary, which goes beyond the estos UCServer SIP (debug) logging

The request for a recording file is made by estos support if required, but can already be taken into account as a precaution when collecting the analysis data in the cases listed below.

Create recording file on the UCServer – basis for analysis

The generation of a recording file via the PCAP programming interface on the UCServer can be useful, for example, to record

  • the complete SIP communication between PBX and UCServer in case of possibly disturbed SIP communication
  • of the audio data between telephone system and UCServer (RTP) to observe the audio quality (delay, jitter, loss)

  • of the audio data between UCServer and ProCall Client (SRTP) to observe the audio quality (delay, jitter, loss)

  • the STUN (bind requests) and TURN operations (allocations, channels) for ICE handshaking

  • disturbed communication relations (firewall operations, NAT operations, ICMP errors)

  • of DTLS handshaking and key exchange between UCServer and ProCall Client

PCAP recording on host of ProCall clients

In special analysis situations, the PCAP recording can also be useful on the host of the ProCall Enterprise clients, e.g. to compare the change in media jitter on the interfaces of server and client or to identify packet delay between the hosts.

PCAP recording with estos server services on more than one host

If an estos UC media server service operated remotely from the estos UC server service on another host is in use, a PCAP recording on the other UC media server host may also be required to examine RTP audio streams and the associated connection negotiation.
If these services are run separately on separate hosts, the PCAP recording on the estos UCServer host will only include the SIP and SDP communication, and the PCAP recording on the estos UC Media Server host will capture the audio streaming for subsequent analysis.

Care should be taken to use capture filters only as needed to reduce the size of PCAP logs.

Since ProCall Enterprise uses both IPv4 and IPv6, TCP and UDP are used for transport, and communication can take place via all network interfaces (including localhost communication), essential information must not be excluded from capturing and all relevant network interfaces must be activated for capturing.

Wireshark packet sniffer

A frequently used sniffer packet is the network analysis software Wireshark, which is available as free software under GPL license.

Display filter statements frequently used in Wireshark

  • IPv4 destinations: ip.dst==x or ip.src==x
  • UDP destinations: udp.dstport==x or udp.srcport==x
  • SIP dialogs: sip
  • Media streaming: rtp || rtcp
    (due to the encryption of the media stream, the decoding of the stream between UC media server and client may have to be explicitly set to RTP beforehand).
  • STUN/TURN operations: stun || classicstun || turnchannel
  • DTLS handshaking: dtls

How to create a Wireshark trace for the UCServer?

If you have not already done so, install the Wireshark program on the UCServer.

You can find the current version of Wireshark here: https://www.wireshark.org/#download