300-410 VPN Technologies Practice Question
A network engineer is configuring DMVPN Phase 3 with IKEv2. The hub router is a Cisco IOS XE device, and the goal is to allow spoke-to-spoke traffic to bypass the hub after initial registration. Which command must be configured on the hub to enable NHRP redirects?
⚠ Common exam trap
Watch out — candidates often confuse the roles of 'ip nhrp redirect' and 'ip nhrp shortcut', placing the spoke-side command on the hub.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ip nhrp redirect
In DMVPN Phase 3, the hub uses NHRP redirects to inform spokes about a better path to reach another spoke. The 'ip nhrp redirect' command on the hub enables this behavior. Combined with 'ip nhrp shortcut' on the spokes, it allows dynamic direct tunnels. Without the redirect on the hub, spokes continue to route traffic through the hub even if a direct path exists.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ip nhrp map multicast dynamic
Why it's wrong here
'ip nhrp map multicast dynamic' is used on the hub in DMVPN to enable dynamic multicast mapping for routing protocols. It allows the hub to replicate multicast packets to all registered spokes, which is important for protocols like OSPF or EIGRP. However, it does not enable NHRP redirects for spoke-to-spoke direct communication; that is the function of 'ip nhrp redirect'.
- ✓
ip nhrp redirect
Why this is correct
The 'ip nhrp redirect' command is required on the hub in DMVPN Phase 3 to enable NHRP redirect messages. When a spoke sends traffic to the hub for a destination behind another spoke, the hub replies with an NHRP redirect, allowing the spoke to initiate a direct tunnel to the destination spoke. This is a key component of Phase 3 along with 'ip nhrp shortcut' on the spokes.
- ✗
ip nhrp network-id 1
Why it's wrong here
'ip nhrp network-id' is used to identify the NHRP network and must match on all routers in the DMVPN cloud. It is a basic configuration requirement for NHRP to function, but it does not enable redirects. While necessary, it alone does not provide the Phase 3 spoke-to-spoke shortcut capability; the hub still needs 'ip nhrp redirect' to send redirect messages.
- ✗
ip nhrp shortcut
Why it's wrong here
'ip nhrp shortcut' is configured on the spoke routers, not the hub. It allows the spoke to install a shortcut route to a destination spoke when it receives an NHRP redirect or resolution reply. Without this command on the spokes, they cannot dynamically create direct tunnels. The hub requires 'ip nhrp redirect' to send the redirect messages that trigger the shortcut process.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
OSPF Route Summarization and Filtering
Key term
FlexVPN
FlexVPN is a Cisco VPN solution that combines multiple VPN technologies (site-to-site, remote access, and hub-and-spoke) under a single, modular framework based on IKEv2.
Key term
DMVPN Phase 3
DMVPN Phase 3 is a Cisco networking technology that allows branch offices to connect directly to each other without always going through a central hub, but with smarter routing that lets the hub control the traffic paths more efficiently.
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.