Can someone tell me how I can capture packets from an internal ip to see what the user is doing? I mean, I see a user who has a lot of Internet traffic despite having his browsing restricted. How can I to know if teh user are using PSIPHON or ULTRASURF? Can I see something (Intenret page or port) with a packet capture? What would be the syntax to capture the ip user? Thank you!