Thanks Kevin. You give me a glimmer of hope. I'm going to give it a try but it will be difficult for me :) I'm far away from the expert you are. What is the role of stunnel (and/or how to use it) when you sniff with tcpflow. I suppose it gives you opportunity to sniff SSL traffic ? but how ? And Why using tcpflow and not tcpdump nor wireshark ? Thanks in advance -- Fromzy