sshpass -p toor ssh -l root 10.1.1.12 tcpdump -nn -U -s0 -w - -i tap0 'not port 22' | wireshark -k -i -



http://stackoverflow.com/questions/19597903/how-to-capture-remote-system-network-traffic