Ribbon Documentation Portal will be unavailable Thursday February 2nd 2023 between 2:00 PM EST ~ 12:00 PM. More Info
Skip to end of metadata
Go to start of metadata

In this section:


This document describes the ideal settings for a packet capture. For information about how to capture a packet, download, or limitations, see Working with Packet Capture.

Ideal Settings

The following list the ideal settings for Packet Capture.

  1. Packet capture durations should be configured for the minimum amount of time necessary to capture the problem attempting to be reproduced.

  2. When capturing a Media and/or SIP Signaling file, appropriate filters should be selected to minimize the volume of packets that must be captured. In particular, the following two filters should be utilized for Media and/or SIP Signaling file:

    • TCP/UDP Port filters
      Up to four filters can be listed. Separate the filters by using a comma. 

    • Host IP address

      Up to two IP addresses can be configured. If possible, the host IP addresses should be used against termination points that are only terminating a single call. 


      For each IP address entered (Host 1 or Host 2) a new option will become available to select capture direction.

      Other Options Menu


Maximum Duration

The Packet Capture feature is intended for short duration packet captures. For that reason, a maximum duration of 120 minutes (2 hours) is permitted.

Other Recommendations


The packet time-stamps ("Time" field in Wireshark) of media packets in a packet capture may appear wrong, as large negative numbers. However, the ordering of the media packets based on packet numbers ("No." field in Wireshark) will be correct.

Also, if you use the "RTP Player" in Wireshark to decode and play the media packets, the wrong time-stamps may cause noise and/or distortion in the display and audio playback of the media packets. To work around this issue, in the RTP Player of Wireshark, select the "Use RTP timestamp" option and then click Decode.