how to sniffer phone traffic on daisy-chained PC?

Unanswered Question

I am running wireshark on a PC behind my IP phone (7961G). I "enabled" setting

PC Voice VLAN Access*

Span to PC Port*

on this phone.

but I am only seeing multicast/broadcast traffic on the capture (like HSRP from router). No skinny or rtp packets

Is it possible to capture voice packets in this way? or did I miss anything?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 3 (1 ratings)
testeven Tue, 07/28/2009 - 11:21
User Badges:
  • Cisco Employee,

Hi Eric,

Please make sure you are sniffing the correct interface. For example, if you have more than one interface (such as Wireless Ip address or VPN

connection) select the one you want to sniff. Please check the following link, it shows you how to set up a sniffer capture using wireshark:



If you find this post helpful, please rate! :)

testeven Tue, 07/28/2009 - 12:01
User Badges:
  • Cisco Employee,

Try just spanning the port, not the VLAN.

Make sure that you have the following parameters enabled:

Device --> Phone

Select one of the 7961s that's having this issue

Verify that the "PC Voice VLAN Access" is Enabled

Verify that the "Span to PC Port" is Enabled

Update and Reset



CHRIS CHARLEBOIS Mon, 08/03/2009 - 13:00
User Badges:
  • Silver, 250 points or more

It also could be a problem with the NIC itself or with the driver. Some network card and/or drivers do not support promiscuous mode. (I assume that you didn't disable promiscuous mode within Wireshark). Have you used this computer to sniff other network successfully?


This Discussion