hardMultiple Choice
300-410 Practice Question: An engineer configures a DMVPN Phase 2 network…
An engineer configures a DMVPN Phase 2 network with IPsec protection. Spoke-to-spoke tunnels form, but traffic between spokes is not being forwarded directly; it still goes through the hub. The engineer verifies that NHRP registrations are successful and that the spoke-to-spoke IPsec sessions are established. What is the most likely explanation?
⚠ Common exam trap
Cisco often tests the subtle distinction between NHRP resolution success and actual routing table propagation—candidates assume that if NHRP and IPsec are working, traffic must flow directly, but they overlook the hub's routing protocol configuration that prevents spoke-to-spoke route advertisement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The hub router is not configured with the 'no ip split-horizon' command for EIGRP or the 'neighbor' command for OSPF, preventing spoke-to-spoke route propagation.
In a DMVPN Phase 2 network, spoke-to-spoke traffic requires that each spoke learns the remote spoke's prefix via the hub. For EIGRP, the hub must disable split horizon with 'no ip split-horizon eigrp <as>' to propagate routes learned from one spoke to other spokes. Without this, the hub advertises only its own routes, so spokes lack the necessary routing information to forward traffic directly, causing it to be sent through the hub despite working NHRP and IPsec.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The hub router is not configured with the 'no ip split-horizon' command for EIGRP or the 'neighbor' command for OSPF, preventing spoke-to-spoke route propagation.
Why this is correct
In DMVPN Phase 2, the hub must disable split horizon (EIGRP) or use a network type that allows route propagation (OSPF) so that spokes learn each other's subnets. Without this, spokes only have a default route via the hub, so traffic goes through the hub.
- ✗
The IPsec transform set on the spokes uses different encryption algorithms, preventing the spoke-to-spoke tunnel from passing traffic.
Why it's wrong here
IPsec transform sets are negotiated during IKE Phase 2. If the spokes used different encryption algorithms, the IPsec security associations (SAs) for spoke-to-spoke tunnels would not be established at all. Since the question explicitly states IPsec sessions are established, the transform sets must be compatible; mismatched transforms would prevent tunnel formation, not merely redirect traffic through the hub.
- ✗
The NHRP authentication string is mismatched between spokes, causing NHRP resolution to fail.
Why it's wrong here
NHRP authentication is configured on the hub and all spokes using the same string. A mismatch would cause NHRP registration and resolution requests to fail, meaning the spoke would never learn the NBMA address of the other spoke and the dynamic IPsec tunnel would never be created. Because IPsec sessions exist in this scenario, NHRP is functioning correctly; therefore, an NHRP authentication mismatch cannot be the underlying cause.
- ✗
The spoke routers have a static default route pointing to the hub, overriding the dynamic routes.
Why it's wrong here
A static default route has a prefix length of /0, which is less specific than any dynamically learned route to a remote spoke's subnet (e.g., /24). Routing decisions favor the longest prefix match, so a static default route would only be used when no more specific route exists. The real problem is that the hub's split horizon is preventing the propagation of spoke-specific routes, so the spokes have no specific routes to install—not that a default route is overriding them.
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
Learn chapter
Introduction to ENARSI Exam and Network Fundamentals
Key term
DMVPN Phase 2
DMVPN Phase 2 is an advanced Cisco routing technology that allows spoke routers to communicate directly with one another without sending traffic through a central hub, using dynamic routing protocols and multipoint GRE tunnels.
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.