300-410 Layer 3 Technologies Practice Question
A network engineer is troubleshooting a DMVPN Phase 3 network using Cisco IOS XE routers. The hub router is configured with a multipoint GRE tunnel and NHRP. Spoke routers are unable to establish direct spoke-to-spoke tunnels. Which two statements describe the correct operation of DMVPN Phase 3 that could explain the issue? (Choose two.)
⚠ Common exam trap
The trap here is assuming that any NHRP configuration error would cause the same symptom, when in fact Phase 3 requires specific commands on both hub and spokes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The hub must be configured with the ip nhrp redirect command to support Phase 3.
In DMVPN Phase 3, the hub must be configured with ip nhrp redirect, and spokes must be configured with ip nhrp shortcut. The redirect command allows the hub to notify spokes of a better path, while the shortcut command enables spokes to act on those notifications and establish direct tunnels. Without these, spoke-to-spoke traffic will continue to traverse the hub, even if other NHRP settings are correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Spokes must be configured with the ip nhrp network-id command matching the hub.
Why it's wrong here
The ip nhrp network-id command is used to identify the NHRP network. It must match on all routers in the same DMVPN cloud for NHRP to function. However, if the network-id mismatched, NHRP resolution would fail entirely, preventing even spoke-to-hub communication. Since the scenario states that spokes are unable to establish direct spoke-to-spoke tunnels but presumably can reach the hub, a network-id mismatch is not the likely cause. Thus, it is not a correct explanation for the specific issue.
- ✗
The hub must be configured with the ip nhrp map multicast dynamic command.
Why it's wrong here
The ip nhrp map multicast dynamic command is used on the hub to automatically add multicast mappings for spokes. It is commonly used for routing protocol multicast traffic, but it is not specific to Phase 3 operation. While it may be present in a DMVPN configuration, it does not enable or disable spoke-to-spoke shortcut tunnels. Therefore, its absence would not directly cause the failure of direct spoke-to-spoke tunnels in Phase 3.
- ✓
The hub must be configured with the ip nhrp redirect command to support Phase 3.
Why this is correct
In DMVPN Phase 3, the hub must have ip nhrp redirect configured to inform spokes when a better path exists. When the hub receives a packet from a spoke and forwards it to another spoke, it sends an NHRP redirect message to the originating spoke, prompting it to initiate a direct tunnel. Without this command, spokes will not receive the redirect and will continue to route through the hub, preventing direct spoke-to-spoke tunnels.
- ✗
The hub must be configured with the ip nhrp authentication command.
Why it's wrong here
The ip nhrp authentication command is used to authenticate NHRP messages between peers. If authentication is misconfigured, NHRP resolution would fail, affecting all NHRP operations, not just spoke-to-spoke tunnels. While authentication is important for security, it is not a Phase 3-specific requirement for shortcut tunnels. The question asks for statements that describe correct Phase 3 operation that could explain the issue; authentication is not specific to Phase 3. Hence, it is not a correct choice.
- ✓
Spokes must be configured with the ip nhrp shortcut command to support Phase 3.
Why this is correct
In DMVPN Phase 3, spokes must have ip nhrp shortcut enabled to act on NHRP redirect messages. When a spoke receives a redirect, it sends an NHRP resolution request for the target spoke's NBMA address and installs a shortcut route. Without this command, the spoke will not install the shortcut and will continue to forward traffic through the hub. Thus, this is a required configuration for direct spoke-to-spoke communication.
Go deeper
Related to this question
Learn chapter
ACL-Based Traffic Filtering and Policy-Based Routing
Key term
DMVPN Phase 2
DMVPN Phase 2 is an advanced Cisco routing technology that allows spoke routers to communicate directly with one another without sending traffic through a central hub, using dynamic routing protocols and multipoint GRE tunnels.
Key term
DMVPN Phase 3
DMVPN Phase 3 is a Cisco networking technology that allows branch offices to connect directly to each other without always going through a central hub, but with smarter routing that lets the hub control the traffic paths more efficiently.
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.