On Monday, March 7, 2016 8:29:09 PM PST Rob Janssen wrote: ...
The GUI version 'wireshark' can nicely fold and unfold all levels of detail but of course it is more difficult to run it inside a router or small Linux system used as a router.
Running tcpdump on the router with the raw output going to a file and then downloading it to another machine for analysys with wireshark works well. That's how I discovered the foscam camera on my network phoning home to five sites overseas.