
Yeah
A hub and a linux laptop running wireshark thrown in the mix.
Or a bunch of mirroring ports on your backbone transition points and a dual xeon with a 6 port GB card recieving the mirrored traffic, and a process per port saving the last X hours of traffic on a round robin basis on a RAID 1+0 array.
To then go and analyze via Wireshark.
Does it HAVE to be Windows?