Courseiva
Layer 3 Technologies →hardMultiple Choice

300-410 Layer 3 Technologies Practice Question

A network engineer is troubleshooting a DMVPN Phase 3 network using Cisco IOS XE routers. The hub router (Hub1) has a public IP of 203.0.113.1 and is configured with `tunnel mode gre multipoint`. Spoke routers are behind NAT devices. Spoke1 cannot establish a direct spoke-to-spoke tunnel with Spoke2, although both can reach the hub. Which technology must be enabled on the hub to allow spoke-to-spoke direct tunnels in this scenario?

⚠ Common exam trap

Many candidates confuse NHRP redirect (hub) with NHRP shortcut (spoke) and assuming that IPsec or multicast alone can enable spoke-to-spoke tunnels.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NHRP redirect

In DMVPN Phase 3, the hub uses NHRP redirect to notify spokes of a better path to another spoke. When Spoke1 sends traffic to Spoke2 via the hub, the hub sends an NHRP redirect, and Spoke1 then initiates a direct tunnel using NHRP shortcut. This is critical when spokes are behind NAT, as the hub facilitates the initial resolution and redirect.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    NHRP shortcut

    Why it's wrong here

    NHRP shortcut is configured on the spoke routers, not the hub. It allows a spoke to use a direct path when instructed by a redirect. While necessary for Phase 3, the hub must first send redirects. Without redirect on the hub, shortcut alone will not trigger direct tunnels. Thus, this is not the technology that must be enabled on the hub.

  • ✗

    Multicast routing

    Why it's wrong here

    Multicast routing is used for dynamic routing protocols within DMVPN but does not directly enable spoke-to-spoke unicast tunnels. In Phase 3, NHRP redirect and shortcut handle path optimization. Multicast may be used for routing updates, but it is not the technology that must be enabled on the hub to allow direct spoke tunnels.

  • ✓

    NHRP redirect

    Why this is correct

    NHRP redirect allows the hub to inform spokes about a more optimal path to another spoke. When Spoke1 sends traffic to Spoke2 via the hub, the hub sends an NHRP redirect message, prompting Spoke1 to initiate a direct tunnel. This is essential for Phase 3 DMVPN, especially with NAT, as it enables dynamic spoke-to-spoke tunnels without preconfiguration.

  • ✗

    IPsec tunnel protection

    Why it's wrong here

    IPsec tunnel protection encrypts traffic within the DMVPN cloud, but it does not facilitate spoke-to-spoke path optimization. It is required for security but not for enabling direct tunnels. The question focuses on the mechanism that allows the hub to signal spokes to build direct tunnels, which is NHRP redirect, not encryption.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Go deeper

Related to this question

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.