This wiki has been migrated to and is now deprecated. Please use that site instead.
Differences between revisions 1 and 2
Revision 1 as of 2007-06-20 20:20:54
Size: 2331
Editor: 216-230-81-92
Revision 2 as of 2007-06-20 20:37:23
Size: 2669
Editor: 216-230-81-92
Deletions are marked like this. Additions are marked like this.
Line 6: Line 6:
Unistim has a couple layers to it.
       |_sequence number
       |_packet-type (ack,nak,or payload)
   |_Payload (if packet-type == payload)
       |_terminal id (if phone is originator)
       |_command array
             |_supporting data as required

Unified Networks IP Stimulus (UNIStim)

Unistim is a Nortel proprietary VOIP protocol. It is a lower level protocol than ["SIP"] or most other VOIP protocols. It's important to always think of the phone as a very dumb terminal. Whereas with ["SIP"], the phone has a basic understanding of a phone call,in Unistim the phone knows how to send key press events, display text, flash light, and stream audio. All intelligence is at the switch layer. Like ["SIP"] Unistim does use ["RTP"] as its audio transport. Unistim has a couple layers to it. Unistim

  • |_RUDP
    • |_sequence number |_packet-type (ack,nak,or payload)
    |_Payload (if packet-type == payload)
    • |_terminal id (if phone is originator) |_command array
      • |_cmd1
        • |_supporting data as required
        • ...


It is my understanding that Unistim is basically an ["IP"] adaptation of Nortel's DMS protocol.

Protocol dependencies

  • ["UDP"]: Typically, UNIStim uses ["UDP"] as its transport protocol. The well known UDP port for UNISTIM traffic is 5000.

Example traffic

XXX - Add example decoded traffic for this protocol here (as plain text or Wireshark screenshot).


The PROTO dissector is (fully functional, partially functional, not existing, ... whatever the current state is). Also add info of additional Wireshark features where appropriate, like special statistics of this protocol.

Preference Settings

(XXX add links to preference settings affecting how PROTO is dissected).

Example capture file

XXX - Add a simple example capture file to the SampleCaptures page and link from here (see below). Keep this file short, it's also a good idea to gzip it to make it even smaller, as Wireshark can open gzipped files automatically.

  • attachment:SampleCaptures/PROTO.pcap

Display Filter

A complete list of PROTO display filter fields can be found in the [ display filter reference]

  • Show only the PROTO based traffic:


Capture Filter

You cannot directly filter PROTO protocols while capturing. However, if you know the ["TCP"] port used (see above), you can filter on that one.

  • Capture only the PROTO traffic over the default port (80):

     tcp port 80 

  • add link to PROTO specification and where to find additional info on the web about it, e.g.:
  • [ RFC 123] The RFC title - explanation of the RFC content.


UNISTIM (last edited 2008-04-12 17:51:29 by localhost)