300-410 Layer 3 Technologies Practice Question
A network administrator is troubleshooting a DMVPN Phase 3 deployment using mGRE and IPsec. Spoke-to-spoke communication is not working directly; traffic is flowing through the hub. The administrator verifies that NHRP registrations are successful and that the hub has a route to all spokes. Which two actions are required to enable direct spoke-to-spoke communication? (Choose two.)
⚠ Common exam trap
Candidates often confuse where to place 'ip nhrp shortcut' and 'ip nhrp redirect'; the redirect goes on the hub, while the shortcut goes on the spokes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure 'ip nhrp shortcut' on the spoke tunnel interfaces.
DMVPN Phase 3 requires 'ip nhrp redirect' on the hub and 'ip nhrp shortcut' on the spokes to enable direct spoke-to-spoke tunnels. The hub uses redirect to inform the originating spoke of a better path, and the spoke uses shortcut to act on that information and establish a direct tunnel to the destination spoke. Without both, traffic continues to flow through the hub.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure 'ip nhrp network-id' on all tunnel interfaces.
Why it's wrong here
The 'ip nhrp network-id' command is used to identify the NHRP network and must match on all routers for NHRP to function. However, the scenario states that NHRP registrations are successful, indicating that the network-id is already correctly configured. Therefore, this is not a missing action to enable direct spoke-to-spoke communication. The issue lies with redirect and shortcut commands, not the network-id.
- ✓
Configure 'ip nhrp shortcut' on the spoke tunnel interfaces.
Why this is correct
On spoke routers in DMVPN Phase 3, 'ip nhrp shortcut' must be enabled to allow the spoke to install a shortcut route to the destination spoke when it receives an NHRP redirect from the hub. This command enables the spoke to override its default routing and send traffic directly to the destination spoke's NBMA address. Without it, the spoke ignores the redirect and continues to forward traffic through the hub.
- ✓
Configure 'ip nhrp redirect' on the hub tunnel interface.
Why this is correct
In DMVPN Phase 3, the hub must be configured with 'ip nhrp redirect' to inform spokes of a better path to the destination. When the hub receives a packet from a spoke destined to another spoke, it sends an NHRP redirect message to the originating spoke, prompting it to resolve the destination spoke's NBMA address directly. Without this, the spoke continues to send traffic through the hub, preventing direct spoke-to-spoke communication.
- ✗
Configure 'ip nhrp shortcut' on the hub tunnel interface.
Why it's wrong here
'ip nhrp shortcut' is configured on spoke routers, not on the hub. It allows the spoke to use a shortcut path when it receives an NHRP redirect. If configured on the hub, it has no effect for spoke-to-spoke communication because the hub does not need to shortcut; it is the spokes that need to bypass the hub. Therefore, this is not a required action on the hub.
- ✗
Configure 'ip nhrp map' entries for all remote spokes on each spoke.
Why it's wrong here
Static NHRP map entries are not required in DMVPN Phase 3 because dynamic NHRP resolution is used. Spokes learn about other spokes through NHRP redirects and resolutions. While static mappings can be used in Phase 1 or 2, they are not necessary for Phase 3 and would not enable direct communication if the redirect and shortcut mechanisms are not in place. This option is therefore incorrect.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
Device Management and Network Monitoring (SNMP, Syslog, NetFlow)
Key term
DMVPN Phase 2
DMVPN Phase 2 is an advanced Cisco routing technology that allows spoke routers to communicate directly with one another without sending traffic through a central hub, using dynamic routing protocols and multipoint GRE tunnels.
Key term
DMVPN Phase 3
DMVPN Phase 3 is a Cisco networking technology that allows branch offices to connect directly to each other without always going through a central hub, but with smarter routing that lets the hub control the traffic paths more efficiently.
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.