Help us to improve our website!

We want to inspire you for our UCC solution! To do this, we use cookies to provide you with an optimal and personalised website experience. Clicking on "Accept all" allows us to process this data and share it with third-party providers in accordance with our privacy policy. Here you can also adjust the cookie settings at any time.
Technically necessary cookies
Accept all
Save selection

How do I create a Wireshark trace?


A Wireshark trace of the XPhone Server is necessary for the analysis of AnyDevice and softphone signalling problems or no/one-sided speech intelligibility when using the softphone.

If you have not already done so, install the Wireshark program on the XPhone Connect Server.
You can download the latest version of Wireshark here:

During installation, make sure that an npcap driver is usually installed by the XPhone Connect Server installation wizard. This is also offered during the installation of Wireshark, but if there is already a version on the computer, you will be informed of this. A new installation of the npcap driver is not necessary in this case.

Selecting the interfaces

Open Wireshark on the XPhone Connect Server. You will be greeted by this interface:

You will now see the two interfaces Ethernet and Npcap Loopback Adapter (these may be called something else in your case).
If you do not see an interface, try to start Wireshark as administrator or reinstall the npcap driver.

Then mark the Ethernet interface. If you also want to log the softphone signalling, also select the loopback adapter by holding down the CTRL key to select both interfaces (see video).


Define cut filter (optional)

In order to record only the relevant packets via Wireshark, a recording filter can be entered in the input field after marking the desired network interfaces.

If you only want to record the SIP signalling and no voice packets, use one of the ports of the SIP connection XCC <-> telephone system and if necessary one port of the SIP connection XCC <-> XPhone Connect Server (softphone) connection for the softphone signalling.


If you want to record additional voice packets, e.g. to be able to analyse the voice quality, add the portrange 30000-33000 to the recording filter.

In our example, the entire filter is then

port 5068 || port 4901 || portrange 30000-33000

Starting and stopping the recording

Then press the Enter key (while the cursor is in the input field) to start recording for the selected ports with the recording filter.

Now adjust the behaviour. You should be able to find various packages in the upper area.

Important: To stop recording, click on the red square in the upper left corner.

WS Capture

Now save the Wireshark trace via File -> Save.

Other recording options

If a Wireshark trace is intended to capture sporadic behaviour, it can be helpful to save the recording "rolling".

To do this, click on this field before recording:


Select the required interfaces as described at the beginning:


Select the output settings as follows. Do not forget to enter a path with a file name with sufficient free space.


Then click on the Start button. Now two Wireshark traces with 500 MB each are stored in a rolling manner.

If necessary or depending on the instruction, the values of the recording options can of course be adjusted.

The Wireshark trace must now continue to run actively until the desired behaviour is "captured". It can then be stopped normally via the stop button and the files saved.

Subscribe to our Newsletter


Thank you for subscribing. To confirm your subscription, please click the link in your registration email.


An error occured. Please try again.