I would suggest setting up a snort session. www.snort.org
This will allow you to capture all/(or any that you choose) packets traversing your network.
Can't help with the zonealarm side, I use tiny personal software's firewall which logs all traffic on each machine per rules I create.
cheers




