1 | initial version |
I captured the data on the host side,which is windows
Perhaps, as the vEthernet device is, in effect, a local loopback/wraparound device, any time a packet is transmitted on the adapter, it's then received by the "other side" of the adapter, and NDIS sees both packets and delivers both of them to the WinPcap or Npcap driver, so you get two copies.
If you're using Npcap (which is what current versions of Wireshark installs) rather than WinPcap (which hasn't been the default in a while), you might want to report this on the Npcap issue list, as the Npcap developers have more resources and time to look at this, and more familiarity with the Npcap code.