Courseiva
Layer 3 Technologies →hardMultiple Select

300-410 Layer 3 Technologies Practice Question

A network administrator is troubleshooting a DMVPN Phase 3 deployment using mGRE and IPsec. Spoke-to-spoke communication is not working directly; traffic is flowing through the hub. The administrator verifies that NHRP registrations are successful and that the hub has a route to all spokes. Which two actions are required to enable direct spoke-to-spoke communication? (Choose two.)

⚠ Common exam trap

Candidates often confuse where to place 'ip nhrp shortcut' and 'ip nhrp redirect'; the redirect goes on the hub, while the shortcut goes on the spokes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure 'ip nhrp shortcut' on the spoke tunnel interfaces.

DMVPN Phase 3 requires 'ip nhrp redirect' on the hub and 'ip nhrp shortcut' on the spokes to enable direct spoke-to-spoke tunnels. The hub uses redirect to inform the originating spoke of a better path, and the spoke uses shortcut to act on that information and establish a direct tunnel to the destination spoke. Without both, traffic continues to flow through the hub.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure 'ip nhrp network-id' on all tunnel interfaces.

    Why it's wrong here

    The 'ip nhrp network-id' command is used to identify the NHRP network and must match on all routers for NHRP to function. However, the scenario states that NHRP registrations are successful, indicating that the network-id is already correctly configured. Therefore, this is not a missing action to enable direct spoke-to-spoke communication. The issue lies with redirect and shortcut commands, not the network-id.

  • ✓

    Configure 'ip nhrp shortcut' on the spoke tunnel interfaces.

    Why this is correct

    On spoke routers in DMVPN Phase 3, 'ip nhrp shortcut' must be enabled to allow the spoke to install a shortcut route to the destination spoke when it receives an NHRP redirect from the hub. This command enables the spoke to override its default routing and send traffic directly to the destination spoke's NBMA address. Without it, the spoke ignores the redirect and continues to forward traffic through the hub.

  • ✓

    Configure 'ip nhrp redirect' on the hub tunnel interface.

    Why this is correct

    In DMVPN Phase 3, the hub must be configured with 'ip nhrp redirect' to inform spokes of a better path to the destination. When the hub receives a packet from a spoke destined to another spoke, it sends an NHRP redirect message to the originating spoke, prompting it to resolve the destination spoke's NBMA address directly. Without this, the spoke continues to send traffic through the hub, preventing direct spoke-to-spoke communication.

  • ✗

    Configure 'ip nhrp shortcut' on the hub tunnel interface.

    Why it's wrong here

    'ip nhrp shortcut' is configured on spoke routers, not on the hub. It allows the spoke to use a shortcut path when it receives an NHRP redirect. If configured on the hub, it has no effect for spoke-to-spoke communication because the hub does not need to shortcut; it is the spokes that need to bypass the hub. Therefore, this is not a required action on the hub.

  • ✗

    Configure 'ip nhrp map' entries for all remote spokes on each spoke.

    Why it's wrong here

    Static NHRP map entries are not required in DMVPN Phase 3 because dynamic NHRP resolution is used. Spokes learn about other spokes through NHRP redirects and resolutions. While static mappings can be used in Phase 1 or 2, they are not necessary for Phase 3 and would not enable direct communication if the redirect and shortcut mechanisms are not in place. This option is therefore incorrect.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.