Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
trsantos
Contributor

RTP traffic doesn't show in the logs

Hi people,

We have a CCTV system in the company and I'm analysing this communication in the checkpoint, but I can't see any RTP packets flowing through the gateways. I can see the RTSP (control packets) traffic when the camera is initializing but can't see subsequent RTP traffic (the real stream) coming afterwards. I already checked the specific rule for this traffic, and it set to log it, however I can only see this traffic on Wireshark capturing in the local machine. I'm assuming the traffic like this (stream) is not logged by default, as it doesn't make sense to log every packet of stream for every camera.

 

rtp_packes.png

Is there any hidden option to enable this log? maybe something specific for UDP/stream?

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

What services are you using in your rules to allow the traffic?

0 Kudos
trsantos
Contributor

We are using "Any" for this particular traffic, and I can only see this rule logging rtsp on tcp/554, although I can see the higher ports (50004 on this specific case, it uses dynamic ports) via fw monitor.

fw_rtsp.png

 

 

 

0 Kudos
PhoneBoy
Admin
Admin

RTSP is a "Match for Any" service, which is why it's being used.
I assume it is not logging the data stream by design, but TAC would have to to confirm.

Not sure there's an option in this service to enable logging the data stream, but you can disable this service (and handler) from being matched by opening up the service and unchecking the "match for any" option.

image.png

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 18 Mar 2025 @ 09:30 AM (EET)

    CheckMates Live Greece

    Tue 25 Mar 2025 @ 12:00 PM (MDT)

    Salt Lake City: CPX 2025 Recap

    Tue 08 Apr 2025 @ 12:00 PM (MDT)

    Denver: CPX 2025 Recap
    CheckMates Events