Emergency server help: get in touch

Troubleshoot SIP Calls with sngrep and the Asterisk PJSIP Logger

How to use sngrep and the Asterisk PJSIP logger to capture a failing call, read the SIP ladder, save a pcap, check RTP audio, and find NAT, codec and authentication problems on Asterisk and FreePBX.

Published 5 min read

sngrep is a terminal tool that captures SIP traffic and draws each call as a ladder diagram, which makes most VoIP faults visible in seconds: who sent what, which response failed, which codecs were offered, and which addresses each side asked to receive audio on. This guide covers installing it, capturing and reading a call, saving a capture to share, checking the RTP audio, and the Asterisk logger as an alternative when sngrep is not available.

Short answer: Install sngrep (apt install sngrep, or from EPEL on AlmaLinux and Rocky), run sngrep -d any port 5060, make a test call, select it and press Enter for the ladder. Press F2 to save it as a pcap or text file. If audio is the problem, check the c= and m=audio lines in each SDP: a private address in the PBX’s offer to the provider means one-way audio.

Install sngrep

# Debian / Ubuntu
apt install sngrep

# AlmaLinux / Rocky 8-10
dnf install epel-release
dnf install sngrep

sngrep -V

sngrep needs root (or the capture capability) to read packets. It does not change anything on the server, so it is safe on a live PBX.

Capture and read a call

sngrep -d any port 5060          # all interfaces, SIP on 5060
sngrep -c -d any port 5060       # only calls (INVITE dialogs), hide OPTIONS and REGISTER

The first screen lists dialogs as they happen. Make the test call, highlight it with the arrow keys and press Enter. The ladder shows each host as a column and each SIP message as an arrow. Press Enter on a message to see it in full, and F6 for the raw text. Things to look for:

  • The final response: the first 4xx, 5xx or 6xx is the reason the call failed. Look it up in the SIP response codes tool.
  • Repeated arrows: the same INVITE or 200 OK sent again and again means the other side is not receiving it or its reply is lost.
  • Missing ACK: a 200 OK with no ACK after it ends in a BYE about 32 seconds later.
  • SDP: the c= line is where that side wants audio sent, and m=audio gives the port and codecs.

Filter, save and share a capture

Press F7 to filter by number, method or address, and Space to select several dialogs. F2 saves the selection as a pcap (for Wireshark) or plain text. You can also capture straight to a file on a busy server and read it later:

sngrep -d any -O /root/sip-$(date +%F).pcap port 5060    # capture to a file
sngrep -I /root/sip-2026-10-03.pcap                        # read it back

The text export pastes straight into our SIP trace analyzer, which lists NAT, codec and timer problems for you. Replace phone numbers and remove any Authorization headers before you send a capture to anyone else.

Check the audio (RTP)

SIP sets up the call, RTP carries the voice. When signalling looks right but there is no audio, check whether RTP packets are flowing in both directions:

# RTP between the PBX and the provider's media address (from the SDP)
tcpdump -ni any udp portrange 10000-20000 and host 203.0.113.30 -c 50

# or from the Asterisk CLI during a call
rtp set debug ip 203.0.113.30
rtp set debug off

Packets in only one direction mean a firewall or NAT problem on the side that is not receiving: check that the RTP range is open and that the PBX advertises its public IP. sngrep can also record RTP with sngrep -r, and Wireshark’s Telephony, VoIP Calls menu can play the audio from a pcap.

Use the Asterisk logger instead

When you cannot install packages, Asterisk’s own logger prints every SIP message it sends and receives to the CLI:

asterisk -rvvv
pjsip set logger host 203.0.113.20
# make the call
pjsip set logger off

The logger sees messages after Asterisk has decrypted TLS, which sngrep cannot, but it only shows Asterisk’s view: if a router or SIP ALG changes packets on the way, compare with a capture taken outside the PBX.

Troubleshooting SIP with sngrep at a glance

Troubleshoot SIP Calls with sngrep and the Asterisk PJSIP Lo summary card: Install sngrep (apt install sngrep, or from EPEL on AlmaLinux and Rocky), run sngrep -d any port 5060, make a test…
In short: Install sngrep (apt install sngrep, or from EPEL on AlmaLinux and Rocky), run sngrep -d any port 5060, make a test call, select it and press Enter for the ladder.
Troubleshoot SIP Calls with sngrep and the Asterisk PJSIP Lo sections: Install sngrep, Capture and read a call, Filter, save and share a capture and Check the audio (RTP)
Covers: Install sngrep, Capture and read a call, Filter, save and share a capture and Check the audio (RTP).
Troubleshoot SIP Calls with sngrep and the Asterisk PJSIP Lo questions answered: Can sngrep see SIP over TLS? Is it safe to run sngrep on a production PBX?
Answers: Can sngrep see SIP over TLS? Is it safe to run sngrep on a production PBX?

Official documentation: sngrep, tcpdump manual, Asterisk documentation, Wireshark VoIP calls.

Related: SIP trace analyzer · SIP error codes · Fix one-way audio · Disable SIP ALG.

Frequently asked questions

Can sngrep see SIP over TLS?

Not the content. With TLS on port 5061 the packets are encrypted, so use the Asterisk pjsip logger, which shows the decrypted messages, or test with UDP temporarily.

Is it safe to run sngrep on a production PBX?

Yes. It only reads packets and does not change the system. On a very busy server, filter by port or host and use -c to limit memory use, or capture to a file with -O.

Why does sngrep show nothing?

Run it as root, choose the right interface (-d any), and check the port: providers often use 5060 but some use 5080 or another port, and TLS on 5061 shows encrypted packets only.

How do I capture a call that happens at random times?

Capture to a rotating file with sngrep -O or tcpdump -C/-W, then open it with sngrep -I when the fault is reported.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.