hardMultiple Select
DMVPN Phase 2 Operation: Spoke-to-Spoke Tunnels
Which TWO statements about the operation of DMVPN Phase 2 are true? (Choose TWO.)
Quick Answer
The correct answer is that the hub router must be configured with the 'ip nhrp redirect' command, and spoke-to-spoke tunnels are built dynamically using NHRP redirect and shortcut routes. In DMVPN Phase 2 operation, when a spoke sends traffic to another spoke’s destination behind its tunnel, the hub intercepts the packet and sends an NHRP Redirect message back to the source spoke, revealing the target spoke’s NBMA address. The source spoke then uses its 'ip nhrp shortcut' configuration to initiate a direct spoke-to-spoke tunnel, bypassing the hub for subsequent data flows. On the Cisco CCNP ENARSI 300-410 exam, this concept tests your understanding of how Phase 2 differs from Phase 1 and Phase 3, with a common trap being the belief that spoke-to-spoke traffic always transits the hub after the shortcut is established. A useful memory tip is to think of the hub as a “matchmaker” that introduces spokes via redirect, but does not stay in the conversation.
⚠ Common exam trap
Candidates often confuse DMVPN Phase 1 (hub-only transit, no spoke-to-spoke) with Phase 2 (direct spoke tunnels via NHRP redirect), causing candidates to pick 'all traffic traverses the hub' or to omit the redirect command.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Spoke routers can dynamically establish direct tunnels with each other.
Option A is correct because DMVPN Phase 2 is specifically designed to allow spoke routers to dynamically build direct spoke-to-spoke mGRE tunnels, bypassing the hub for data traffic after NHRP resolution. Option B is correct because the hub must be configured with 'ip nhrp redirect' so that when it forwards a packet from one spoke to another, it sends an NHRP redirect message telling the source spoke to resolve the destination spoke's NBMA address and build a direct tunnel. Option C is incorrect because the hub uses a multipoint GRE (mGRE) tunnel interface, not point-to-point GRE, to support multiple spokes. Option D is incorrect because in Phase 2, spoke-to-spoke traffic does not have to traverse the hub after the direct tunnel is established. Option E is incorrect because NHRP is essential in Phase 2 for mapping tunnel IP addresses to NBMA addresses and enabling dynamic spoke-to-spoke resolution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Spoke routers can dynamically establish direct tunnels with each other.
Why this is correct
DMVPN Phase 2 permits spokes to build direct spoke-to-spoke GRE tunnels on demand, bypassing the hub for data forwarding once NHRP resolution succeeds. Traffic initially traverses the hub, which then signals the shorter path, satisfying the direct-tunnel requirement.
- ✓
The hub router must be configured with the 'ip nhrp redirect' command.
Why this is correct
In DMVPN Phase 2 the hub requires ip nhrp redirect so it can inform a spoke that a superior path to the destination exists, triggering the spoke to resolve the target's NBMA address and build a direct tunnel rather than continuing through the hub.
- ✗
The hub router must use a point-to-point GRE tunnel interface.
Why it's wrong here
DMVPN Phase 2 requires a multipoint GRE (mGRE) tunnel interface on the hub, so a point-to-point GRE interface cannot form the spoke-to-spoke shortcut switching that defines Phase 2. Point-to-point GRE suits static hub-to-spoke tunnels in Phase 1, where all inter-spoke traffic still traverses the hub.
- ✗
All spoke-to-spoke traffic must traverse the hub router.
Why it's wrong here
Phase 2 permits direct spoke-to-spoke tunnels, so traffic need not transit the hub. Hub transit is tempting because it describes Phase 1 and Phase 3 fallback behaviour, but Phase 2's defining feature is spoke-to-spoke shortcut paths.
- ✗
NHRP is not required for Phase 2 operation.
Why it's wrong here
NHRP is fundamental to DMVPN Phase 2: it resolves spoke-to-spoke next hops so spokes can build direct tunnels, and without it spokes can only reach each other via the hub. It is tempting because Phase 1's hub-only topology can appear to function without spoke-to-spoke resolution, but Phase 2's direct spoke tunnels depend on NHRP mappings.
Visual reference
Go deeper
Related to this question
Learn chapter
ACL-Based Traffic Filtering and Policy-Based Routing
Key term
DMVPN Phase 2
DMVPN Phase 2 is an advanced Cisco routing technology that allows spoke routers to communicate directly with one another without sending traffic through a central hub, using dynamic routing protocols and multipoint GRE tunnels.
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 300-410
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. In DMVPN Phase 2, what is the default behavior of the 'ip nhrp redirect' command on the hub router?
hard- A.It is enabled by default and causes the hub to send redirect messages to spokes.
- B.It is disabled by default and must be configured for spoke-to-spoke direct communication.
- ✓ C.It is disabled by default and is used in Phase 3 to enable NHRP redirects.
- D.It is enabled by default and is used to disable NHRP shortcut switching.
Why C: In DMVPN Phase 2, the 'ip nhrp redirect' command is not enabled by default on the hub. It is used in Phase 3 to enable NHRP redirects, which allow the hub to inform spokes that a better path exists directly to another spoke. In Phase 2, spoke-to-spoke tunnels are established based on NHRP resolution triggered by traffic, not by redirect messages.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.