I suggest you have a look at IPFM: http://robert.cheramy.net/ipfm/ It can monitor traffic by interface, ip address, netmask, ... You can set up complex options to exclude ips, and you can precisely manage your logfiles. There are also tools to make graphs with the results -- Clément Stenac