300-410 VPN Technologies Practice Question
A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. The hub router must advertise a default route to all spokes, but the spokes should not use the hub as the next hop for spoke-to-spoke traffic; instead, they should dynamically discover a direct path to other spokes. Which NHRP configuration on the hub is required to support this behavior?
⚠ Common exam trap
The trap here is reversing the roles of ip nhrp redirect and ip nhrp shortcut, placing the spoke-side command on the hub.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ip nhrp redirect
DMVPN Phase 3 requires the hub to be configured with ip nhrp redirect on its mGRE interface. This allows the hub to send NHRP redirect messages to spokes when it forwards traffic between them, prompting the source spoke to resolve the destination spoke's NBMA address and build a direct tunnel. The spokes must also be configured with ip nhrp shortcut to use the redirect information. This combination allows the hub to advertise a default route while still enabling dynamic spoke-to-spoke direct paths.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ip nhrp shortcut
Why it's wrong here
ip nhrp shortcut is configured on the spokes, not the hub, to allow them to use the NHRP redirect information and install a direct route to the destination spoke. Configuring it on the hub would not provide the redirect function needed to trigger spoke-to-spoke path discovery. The hub must send redirects, while spokes use shortcuts to act on them, so this option is incorrect for the hub configuration.
- ✓
ip nhrp redirect
Why this is correct
In DMVPN Phase 3, the hub uses ip nhrp redirect to inform a spoke that a better path exists directly to the destination spoke. When the hub receives a packet from one spoke destined to another, it sends an NHRP redirect message to the source spoke, which then initiates an NHRP resolution for the destination spoke's NBMA address. This enables spoke-to-spoke direct tunnels while the hub still advertises a default route, exactly as required.
- ✗
ip nhrp network-id 1
Why it's wrong here
ip nhrp network-id is a mandatory configuration that identifies the NHRP network and must match on all DMVPN routers. While necessary for NHRP operation, it does not enable the hub to redirect spokes for Phase 3 direct spoke-to-spoke communication. The network-id alone does not trigger the redirect messages that allow spokes to dynamically discover a direct path, so it does not satisfy the scenario's requirement.
- ✗
ip nhrp map multicast dynamic
Why it's wrong here
ip nhrp map multicast dynamic enables the hub to dynamically learn spoke multicast mappings for NHRP, which is useful for multicast traffic in DMVPN. However, it does not provide the redirect mechanism required for Phase 3 spoke-to-spoke direct path discovery. Without ip nhrp redirect, the hub will not notify spokes of a better direct path, so spoke-to-spoke traffic would continue to traverse the hub, failing the requirement.
Visual reference
Go deeper
Related to this question
Learn chapter
DMVPN and FlexVPN Technologies
Key term
DMVPN Phase 3
DMVPN Phase 3 is a Cisco networking technology that allows branch offices to connect directly to each other without always going through a central hub, but with smarter routing that lets the hub control the traffic paths more efficiently.
Key term
DMVPN Phase 2
DMVPN Phase 2 is an advanced Cisco routing technology that allows spoke routers to communicate directly with one another without sending traffic through a central hub, using dynamic routing protocols and multipoint GRE tunnels.
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.