Is it possible to detect if a H.323 connection (phone call) is up by simple sniffing traffic on an adjacent node?
The most effective way seems to sniff all the TCP traffic to 1719 (RAS) and 1720 (H.225 signaling) port. You get signaling with high probability. Other ways are much harder.
Other alternative:
The worst thing you can face is H.235 security with signaling protected. Almost nothing will help you in this case ;).