Is there a amprnet wiki page with recommendations and notes on just how to do this?
It depends too much on the layout of your network and the equipment and software you are using how to do this. I normally use tshark (terminal version), unfortunately it can only display a condensed version of each packet that does not show how it is tunneled, or a way-to-verbose version where one packet takes up multiple screens full of data.
The GUI version 'wireshark' can nicely fold and unfold all levels of detail but of course it is more difficult to run it inside a router or small Linux system used as a router.
Rob