hardMultiple Choice
DMVPN Spoke-to-Spoke Tunnel Failure
An engineer configures DMVPN Phase 2 with spoke-to-spoke tunnels. Spokes can ping each other's physical interfaces, but cannot establish a direct tunnel. NHRP registration is successful. Which is the most likely explanation?
⚠ Common exam trap
Cisco often tests the misconception that successful NHRP registration alone guarantees spoke-to-spoke tunnels, when in fact the redirect and shortcut commands are mandatory for Phase 2 dynamic tunnel establishment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The hub is not configured with 'ip nhrp redirect' and the spokes are not configured with 'ip nhrp shortcut'.
In DMVPN Phase 2, spoke-to-spoke tunnels require NHRP redirect and shortcut mechanisms to dynamically build direct tunnels. The hub must be configured with 'ip nhrp redirect' to send redirect messages to spokes, and spokes must have 'ip nhrp shortcut' to install the NHRP-learned /32 host routes for direct traffic. Without these, spokes will forward traffic through the hub even though they can ping each other's physical interfaces, preventing the establishment of a direct tunnel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The hub is not configured with 'ip nhrp redirect' and the spokes are not configured with 'ip nhrp shortcut'.
Why this is correct
In Phase 2 DMVPN, the hub must send NHRP Redirect messages to inform a spoke that the destination is reachable via another spoke's direct tunnel. The spoke must have 'ip nhrp shortcut' enabled to process these redirects and send a Resolution Request to build a direct tunnel. Without these commands, the spoke continues forwarding traffic through the hub, so spoke-to-spoke tunnels never form even though registration succeeds.
- ✗
The spokes have different NHRP authentication strings, causing NHRP resolution to fail.
Why it's wrong here
NHRP authentication is a required parameter in the 'ip nhrp authentication' command on all tunnel interfaces. If the spokes had different authentication strings, the hub would reject their Registration Requests outright, and the NHRP database would never populate. Since the problem statement explicitly states that registration is successful, the authentication strings must match, eliminating this as a cause of the failure.
- ✗
The tunnel interface on the spokes is configured with 'tunnel mode gre multipoint' but the hub uses 'tunnel mode gre ip'.
Why it's wrong here
This option incorrectly reverses the Phase 2 role assignment: the hub must use 'tunnel mode gre multipoint' to maintain a single mGRE interface for all spoke registrations and to send redirects, while spokes also use mGRE to accept incoming direct tunnels from other spokes. If the hub were configured with 'tunnel mode gre ip', it could only form a single point-to-point tunnel, which would prevent more than one spoke from registering at all. The scenario indicates successful registration, so the hub is certainly not using GRE IP.
- ✗
The spokes are using different IPsec transform sets, causing the IPsec tunnel to fail.
Why it's wrong here
IPsec transform sets are negotiated during IKE Phase 2 between each pair of peers, and a mismatch would cause the IPsec tunnel to fail completely. Since the issue is specifically that spokes are not *attempting* to build a direct tunnel (they lack NHRP redirect/shortcut), there is no evidence of any IPsec negotiation failure. Moreover, a transform set mismatch would also affect the initial hub-spoke IPsec tunnel, which is implicitly working for NHRP registration and data forwarding.
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.