Courseiva
Infrastructure Services →mediumMultiple Choice

300-410 Infrastructure Services Practice Question

A network administrator is deploying a DMVPN Phase 3 hub-and-spoke topology. Spokes must be able to communicate directly with each other without traffic traversing the hub. The administrator has configured NHRP and IPsec on all routers. Which additional configuration is required on the hub to enable direct spoke-to-spoke communication?

⚠ Common exam trap

Many candidates confuse NHRP redirect and NHRP shortcut, placing shortcut on the hub instead of the spokes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable NHRP redirect on the hub.

In DMVPN Phase 3, direct spoke-to-spoke communication is achieved by combining NHRP redirect on the hub and NHRP shortcut on the spokes. The hub uses NHRP redirect to inform a spoke that a better path exists to another spoke. The spoke then uses NHRP shortcut to resolve the destination and build a direct tunnel. Without redirect on the hub, spokes never learn about the direct path and continue to forward traffic through the hub, defeating the purpose of Phase 3.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable NHRP shortcut on the hub.

    Why it's wrong here

    NHRP shortcut is configured on the spokes, not the hub. It allows a spoke to use the NHRP resolution information to install a shortcut route to another spoke, bypassing the hub. On the hub, NHRP shortcut is not needed and may cause unexpected behavior. The hub's role is to provide redirect messages, while spokes act on them via shortcut configuration.

  • ✗

    Set the tunnel mode to multipoint GRE on the hub.

    Why it's wrong here

    Multipoint GRE (mGRE) is already required for DMVPN and is typically configured on the hub. However, mGRE alone does not enable direct spoke-to-spoke communication. It allows the hub to have a single tunnel interface for multiple spokes, but additional NHRP features like redirect are needed to facilitate dynamic spoke-to-spoke tunnels.

  • ✓

    Enable NHRP redirect on the hub.

    Why this is correct

    NHRP redirect is essential for DMVPN Phase 3. When the hub receives a packet from one spoke destined to another spoke, it sends an NHRP redirect message to the source spoke, informing it of a better path. The source spoke then initiates an NHRP resolution for the destination spoke's tunnel IP, allowing direct spoke-to-spoke tunnel establishment. Without NHRP redirect, spokes continue sending traffic through the hub even if a direct path exists.

  • ✗

    Configure the hub as a route reflector for BGP.

    Why it's wrong here

    While BGP route reflection can be used in DMVPN to propagate routes, it does not enable direct spoke-to-spoke communication. Route reflection affects control-plane routing, but data-plane forwarding still follows the routing table. Without NHRP redirect and shortcut, spoke-to-spoke traffic would still be routed through the hub even if BGP routes are present.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.