Courseiva
Infrastructure Services →mediumMultiple Choice

300-410 Infrastructure Services Practice Question

A network administrator is deploying DMVPN Phase 3 with IKEv2. The hub router is configured with a dynamic multipoint VPN tunnel and is using NHRP. Spoke routers are configured to register with the hub. After configuration, the administrator notices that spoke-to-spoke traffic is still going through the hub instead of directly between spokes. Which configuration change is most likely to resolve this issue?

⚠ Common exam trap

The trap here is focusing on control plane routing protocols like BGP route reflection, while the issue is about NHRP data plane optimization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable NHRP redirect on the hub and NHRP shortcut on the spokes.

DMVPN Phase 3 requires NHRP redirect on the hub and NHRP shortcut on the spokes to enable direct spoke-to-spoke communication. The hub uses NHRP redirect to inform a spoke that a more efficient path exists directly to another spoke. The spoke then uses NHRP shortcut to resolve the destination and establish a direct tunnel. Without these, traffic will continue to flow through the hub.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable NHRP redirect on the hub and NHRP shortcut on the spokes.

    Why this is correct

    In DMVPN Phase 3, NHRP redirect on the hub allows the hub to inform the spoke that a better path exists directly to another spoke. NHRP shortcut on the spokes allows them to install a direct route to the destination spoke based on the redirect message. Without these, spoke-to-spoke traffic will continue to traverse the hub even if a direct path is available. Enabling these features is essential for Phase 3 direct spoke-to-spoke communication.

  • ✗

    Configure the hub as a route reflector for BGP.

    Why it's wrong here

    A route reflector is used to propagate BGP routes within an autonomous system without requiring a full mesh of iBGP sessions. While BGP is commonly used in DMVPN to exchange routing information, making the hub a route reflector does not enable direct spoke-to-spoke traffic forwarding. The issue is about data plane forwarding, not control plane route propagation. Route reflection alone would not trigger NHRP resolution for direct tunnels.

  • ✗

    Enable split horizon on the hub's tunnel interface.

    Why it's wrong here

    Split horizon is a routing loop prevention mechanism that prevents a route from being advertised back out the interface it was learned from. Enabling split horizon on the hub's tunnel interface could actually prevent routes from being advertised to other spokes, disrupting connectivity. It does not facilitate direct spoke-to-spoke tunnels. In fact, split horizon is typically disabled on DMVPN hub tunnel interfaces to allow full route propagation.

  • ✗

    Change the tunnel mode from GRE multipoint to GRE point-to-point.

    Why it's wrong here

    DMVPN requires multipoint GRE (mGRE) on the hub to support multiple dynamic tunnels. Changing to point-to-point GRE would break the dynamic tunnel establishment and prevent spokes from forming tunnels with the hub or each other. This would not enable direct spoke-to-spoke communication; instead, it would disable the DMVPN functionality entirely. The tunnel mode must remain mGRE for DMVPN to operate.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

Go deeper

Related to this question

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.