Packet capture on SBC

Status
Not open for further replies.

Goran Cvijanovic

Advanced Certified
Joined
Jul 26, 2018
Messages
45
Reaction score
3
Hello,

I'm using SBC on all PBXs that I manage, and I think it is great, but I still miss some details and I hope someone will be able to shed some light on this.

I have 2 locations with SBC connected to the PBX (AWS), and I want to do packet capture and analyze the call.
The problem is that I only see this info when I make the call.13163
So, this packet capture was taken on my SBC, and here I only see traffic between 192.168.2.25 (phone) and 192.168.2.22 (SBC), but call leg between SBC and PBX is missing (everything works over the same eth0 interface, so it's not using different interface to reach PBX).
I'm assuming that Wireshark isn't able to detect SIP traffic over encrypted tunnel on port 5090.
Question, can I somehow configure Wireshark to see encrypted traffic by telling it to check port 5090 and use key to decrypt that traffic?
If there is a tutorial for this on the 3cx site or forum, then I wasn't able to find it, and would like to learn how to do this because I need this in order to see complete call flow from SBC point of view.
 
I'm assuming that Wireshark isn't able to detect SIP traffic over encrypted tunnel on port 5090.

Yes I would agree, this has been an issue for me in the past also, the traffic is encrypted and thus not view-able, also in most cases devices connected via an SBC do not require "PBX delivers audio" to be enabled on their extensions this can also remove the audio path from the trace as well.
 
Is there any difference when "PBX Delivers audio" is enabled on extension behind SBC? I mean, all traffic is anyway using SBC or I got it wrong?
 
If an SBC is used at a site, then any voice packets, would normally go direct between devices, at that location, not back through the PBX.

PBX Delivers Audio will force voice packets to go back though the PBX. This is usually used to "fix" audio issues, when devices at a site are using STUN.
 
Last edited:
If an SBC is used at a site, then any voice packets would normally go direct from one device, at that location, not back through the PBX.
Unless you are using call recording, then the PBX is in the route always.
 
Ok, but what about packet capture? I have 2 locations with phone and SBC on each, and I can't see all call legs because of encryption. Is there a solution for this or no? I also tried disabling encryption on the SBC, but then SBC starts reconnecting every 30 seconds and I can't make it work properly.
 
Ok, but what about packet capture? I have 2 locations with phone and SBC on each, and I can't see all call legs because of encryption. Is there a solution for this or no? I also tried disabling encryption on the SBC, but then SBC starts reconnecting every 30 seconds and I can't make it work properly.
If you need to wireshark between SBCs or between the SBC and the PBX, then no, you can't because of the encryption and it's not possible to disable this.

One solution would be to provision both phones on each location via STUN so you can capture the traffic.

If you need to capture between local phones, this should work via port mirroring on your switch. Some even have the capture built-in and most phones do too.
 
I want to capture traffic between 2 phones on different locations. I also tried using packet capture on the phone itself, but it also shows only what is happening between phone and SBC, and everything else is hidden shall we say. So, idea is to have both call legs, one between phone and SBC, and another between SBC and PBX if possible.
It's hard to believe that this isn't possible when using SBC.
 
I want to capture traffic between 2 phones on different locations. I also tried using packet capture on the phone itself, but it also shows only what is happening between phone and SBC, and everything else is hidden shall we say. So, idea is to have both call legs, one between phone and SBC, and another between SBC and PBX if possible.
It's hard to believe that this isn't possible when using SBC.
No it's not possible with an SBC in the way.

I would recommend trying the STUN way temporarily.
 
Ok, but what about packet capture? I have 2 locations with phone and SBC on each, and I can't see all call legs because of encryption. Is there a solution for this or no? I also tried disabling encryption on the SBC, but then SBC starts reconnecting every 30 seconds and I can't make it work properly.
Hi Goran,

You cannot decrypt the the SBC traffic via wireshark. You can setup the SBC to have no encryption though and I don;t know why you had trouble with that part. You just change the setting on the management console and then push the config using the button on top (or setup the SBC from scratch).

You never actually said what issue you are trying to resolve, unless you are just doing this for educational purposes ;)
 
Yeah it's mostly educational, but I want to be ready in case of a problem. Anyway, when I converted SBC to no encryption, presence stops working and SBC reconnects evey 30 seconds. I was able to make calls, but they drop when SBC disconnects. I can again make a call when SBC reconnects, but presence is never restored until I return back to encrypted. I used Push Config button and checked configuration to make sure that SBC got it, and it did indeed but problem preserved.
Just try on your own, I think this isn't related to me only because I tried that with PI3 and then with PI4 that I received few days ago and freshly installed it.
 
Hi Goran,

A couple of things to clarify first:

- Presence does not exist on SBC, that's more of a mobile/web/desktop client thing where you see the status of your colleagues (i.e green,red,yellow status square - not BLFs if that's what you meant?)

- Pi4 is not supported at this point so I would not include it any of my tests, use 3B+ for now

- Seeing the SBC disconnect/reconnect is indication of a network issue or misconfiguration perhaps

I can suggest the following though:
  • Ensure you are running 3CX V16 SP3 (16.0.3.676)
  • Ensure the Pi 3B+ is running our provided image from our guide
  • Purge the SBC installation off the Pi 3B+
  • Change the SBC settings in the management console to "TCP" instead of "TLS" Security
  • Reinstall the SBC (should be v16.0.390 now)
  • You should see it come online in the management console and the statistics page will show "TCP Encrypted No"
The connection should remain stable in this case, if you still have disconnections you will have to look a bit further into your network (ie. firewall may be doing something you are unaware of). From here my test Pi seems very stable without TLS, connecting to a google cloud instance PBX.

https://www.3cx.com/docs/installing-pbx-raspberry-pi/
https://www.3cx.com/docs/3cx-tunnel-session-border-controller/#h.klea23ed8e99
 
Yeah, BLFs are not showing when tunnel is connected without encryption, which is fixed right away after I enable it. When tunnel is up with encryption my phone works perfect.
 
Given that BLFs work over SUBSCRIBE and NOTIFY, if that does not work without the encryption I would suspect something may be modifying the messages (SIP ALG perhaps?)

Regardless, I can confirm that unencrypted SBC allows BLF to work fine when testing here.
 
  • Like
Reactions: Evolute IT
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,934
Messages
589,821
Members
164,813
Latest member
divdigital