This wiki has been migrated to https://gitlab.com/wireshark/wireshark/-/wikis/home and is now deprecated. Please use that site instead.

Session Initiation Protocol (SIP)

The Session Initiation Protocol (SIP) is an application-layer control (signaling) protocol for sessions.

These sessions include Internet telephone calls, multimedia distribution, and multimedia conferences. SIP can create, modify, and terminate sessions with one or more participants.

The SIP protocol is a member of the ["VOIPProtocolFamily"].

History

XXX - add a brief description of SIP history

Protocol dependencies

Example traffic

attachment:SIP.jpg

Wireshark

The SIP dissector is fully functional. You can also view SIP message statistics (Statistics | SIP...) or view SIP call flow graphs (Statistics | VoIP Calls)

Preference Settings

Example capture file

attachment:SampleCaptures/aaa.pcap Sample SIP and RTP traffic.

Display Filter

A complete list of SIP display filter fields can be found in the [http://www.wireshark.org/docs/dfref/s/sip.html display filter reference]

Capture Filter

You cannot directly filter SIP protocols while capturing. However, if you know the ["UDP"] or ["TCP"] or port used (see above), you can filter on that one.

["IETF"] Charters:

RFC:

Implementations:

Discussion