I love m0n0wall for this ability beyond any other firewall. (OK, pfSense can do it to)
Go to firewall states. Click "Start New" to start a new baseline. After a few seconds, click "View Delta." You are not looking at all of the conversations for those few seconds. (or minutes) If you do not view the delta, it is just all the conversations that have not times out, so a long lived but slow connection could be artificially high.
Either way, you don't just see that Bob is hogging bandwidth, you see that Bob is hogging bandwidth to Pandora, and Last FM! And Shelly is not far behind with gmail.
You get the point? Very powerful, and extremely granular. It also gives you the ability to just block Pandora for Bob and no one else. When he comes to ask about it, you can have a quiet chat.
OK, I am a bofh...
I admit it.