i see bogus ip header length messages in wireshark when it hasn't been configured correctly. the ITP phones use UDP9000 for the RTP traffic, this is also used by the PCLI protocol. Also you need to make sure you are using g.711 for the codec as all the voip call recorders i've seen can't decode g.729(a) i can send you the guide samsung here wrote on howto use wireshark as this may assist as it talks about all the settings for wireshark to decode the RTP stream