300-410 Infrastructure Services Practice Question
A network administrator is deploying a DMVPN Phase 3 hub-and-spoke topology. Spokes must be able to communicate directly with each other without traffic traversing the hub. The administrator has configured NHRP and IPsec on all routers. Which additional configuration is required on the hub to enable direct spoke-to-spoke communication?
⚠ Common exam trap
Many candidates confuse NHRP redirect and NHRP shortcut, placing shortcut on the hub instead of the spokes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable NHRP redirect on the hub.
In DMVPN Phase 3, direct spoke-to-spoke communication is achieved by combining NHRP redirect on the hub and NHRP shortcut on the spokes. The hub uses NHRP redirect to inform a spoke that a better path exists to another spoke. The spoke then uses NHRP shortcut to resolve the destination and build a direct tunnel. Without redirect on the hub, spokes never learn about the direct path and continue to forward traffic through the hub, defeating the purpose of Phase 3.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable NHRP shortcut on the hub.
Why it's wrong here
NHRP shortcut is configured on the spokes, not the hub. It allows a spoke to use the NHRP resolution information to install a shortcut route to another spoke, bypassing the hub. On the hub, NHRP shortcut is not needed and may cause unexpected behavior. The hub's role is to provide redirect messages, while spokes act on them via shortcut configuration.
- ✗
Set the tunnel mode to multipoint GRE on the hub.
Why it's wrong here
Multipoint GRE (mGRE) is already required for DMVPN and is typically configured on the hub. However, mGRE alone does not enable direct spoke-to-spoke communication. It allows the hub to have a single tunnel interface for multiple spokes, but additional NHRP features like redirect are needed to facilitate dynamic spoke-to-spoke tunnels.
- ✓
Enable NHRP redirect on the hub.
Why this is correct
NHRP redirect is essential for DMVPN Phase 3. When the hub receives a packet from one spoke destined to another spoke, it sends an NHRP redirect message to the source spoke, informing it of a better path. The source spoke then initiates an NHRP resolution for the destination spoke's tunnel IP, allowing direct spoke-to-spoke tunnel establishment. Without NHRP redirect, spokes continue sending traffic through the hub even if a direct path exists.
- ✗
Configure the hub as a route reflector for BGP.
Why it's wrong here
While BGP route reflection can be used in DMVPN to propagate routes, it does not enable direct spoke-to-spoke communication. Route reflection affects control-plane routing, but data-plane forwarding still follows the routing table. Without NHRP redirect and shortcut, spoke-to-spoke traffic would still be routed through the hub even if BGP routes are present.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
Device Management and Network Monitoring (SNMP, Syslog, NetFlow)
Key term
DMVPN Phase 3
DMVPN Phase 3 is a Cisco networking technology that allows branch offices to connect directly to each other without always going through a central hub, but with smarter routing that lets the hub control the traffic paths more efficiently.
Key term
DMVPN Phase 2
DMVPN Phase 2 is an advanced Cisco routing technology that allows spoke routers to communicate directly with one another without sending traffic through a central hub, using dynamic routing protocols and multipoint GRE tunnels.
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.