300-410 Infrastructure Services Practice Question
A network administrator is deploying DMVPN Phase 3 with IKEv2. The hub router is configured with a dynamic multipoint VPN tunnel and is using NHRP. Spoke routers are configured to register with the hub. After configuration, the administrator notices that spoke-to-spoke traffic is still going through the hub instead of directly between spokes. Which configuration change is most likely to resolve this issue?
⚠ Common exam trap
The trap here is focusing on control plane routing protocols like BGP route reflection, while the issue is about NHRP data plane optimization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable NHRP redirect on the hub and NHRP shortcut on the spokes.
DMVPN Phase 3 requires NHRP redirect on the hub and NHRP shortcut on the spokes to enable direct spoke-to-spoke communication. The hub uses NHRP redirect to inform a spoke that a more efficient path exists directly to another spoke. The spoke then uses NHRP shortcut to resolve the destination and establish a direct tunnel. Without these, traffic will continue to flow through the hub.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable NHRP redirect on the hub and NHRP shortcut on the spokes.
Why this is correct
In DMVPN Phase 3, NHRP redirect on the hub allows the hub to inform the spoke that a better path exists directly to another spoke. NHRP shortcut on the spokes allows them to install a direct route to the destination spoke based on the redirect message. Without these, spoke-to-spoke traffic will continue to traverse the hub even if a direct path is available. Enabling these features is essential for Phase 3 direct spoke-to-spoke communication.
- ✗
Configure the hub as a route reflector for BGP.
Why it's wrong here
A route reflector is used to propagate BGP routes within an autonomous system without requiring a full mesh of iBGP sessions. While BGP is commonly used in DMVPN to exchange routing information, making the hub a route reflector does not enable direct spoke-to-spoke traffic forwarding. The issue is about data plane forwarding, not control plane route propagation. Route reflection alone would not trigger NHRP resolution for direct tunnels.
- ✗
Enable split horizon on the hub's tunnel interface.
Why it's wrong here
Split horizon is a routing loop prevention mechanism that prevents a route from being advertised back out the interface it was learned from. Enabling split horizon on the hub's tunnel interface could actually prevent routes from being advertised to other spokes, disrupting connectivity. It does not facilitate direct spoke-to-spoke tunnels. In fact, split horizon is typically disabled on DMVPN hub tunnel interfaces to allow full route propagation.
- ✗
Change the tunnel mode from GRE multipoint to GRE point-to-point.
Why it's wrong here
DMVPN requires multipoint GRE (mGRE) on the hub to support multiple dynamic tunnels. Changing to point-to-point GRE would break the dynamic tunnel establishment and prevent spokes from forming tunnels with the hub or each other. This would not enable direct spoke-to-spoke communication; instead, it would disable the DMVPN functionality entirely. The tunnel mode must remain mGRE for DMVPN to operate.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
Device Management and Network Monitoring (SNMP, Syslog, NetFlow)
Key term
DMVPN Phase 3
DMVPN Phase 3 is a Cisco networking technology that allows branch offices to connect directly to each other without always going through a central hub, but with smarter routing that lets the hub control the traffic paths more efficiently.
Key term
DMVPN Phase 2
DMVPN Phase 2 is an advanced Cisco routing technology that allows spoke routers to communicate directly with one another without sending traffic through a central hub, using dynamic routing protocols and multipoint GRE tunnels.
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.