This document describes the ideal settings for a packet capture. For information about how to capture a packet, download, or limitations, see Working with Packet Capture.
The following list the ideal settings for Packet Capture.
Host IP address
Up to two IP addresses can be configured. If possible, the host IP addresses should be used against termination points that are only terminating a single call.
For each IP address entered (Host 1 or Host 2) a new option will become available to select capture direction.
The Packet Capture feature is intended for short duration packet captures. For that reason, a maximum duration of 120 minutes (2 hours) is permitted.
The packet time-stamps ("Time" field in Wireshark) of media packets in a packet capture may appear wrong, as large negative numbers. However, the ordering of the media packets based on packet numbers ("No." field in Wireshark) will be correct.
Also, if you use the "RTP Player" in Wireshark to decode and play the media packets, the wrong time-stamps may cause noise and/or distortion in the display and audio playback of the media packets. To work around this issue, in the RTP Player of Wireshark, select the "Use RTP timestamp" option and then click Decode.