It may be possible to launch tcpdump in the ephemeral vs-debug container and then stream captured packets into WireShark running on the workstation. This would be a super sweet way to examine network traffic on the target container.
https://medium.com/codex/capture-tcpdump-with-ksniff-and-wireshark-from-kubernetes-c212b93ff9f9