I'd go for Ethereal it's excellent, you can find the packets you're really interested in, and it disassembles them for you, separating the headers at various protocol levels, which makes it much...