Courseiva
hardMultiple Choice

300-410 Practice Question: An engineer configures a DMVPN Phase 2 network…

An engineer configures a DMVPN Phase 2 network with IPsec protection. Spoke-to-spoke tunnels form, but traffic between spokes is not being forwarded directly; it still goes through the hub. The engineer verifies that NHRP registrations are successful and that the spoke-to-spoke IPsec sessions are established. What is the most likely explanation?

⚠ Common exam trap

Cisco often tests the subtle distinction between NHRP resolution success and actual routing table propagation—candidates assume that if NHRP and IPsec are working, traffic must flow directly, but they overlook the hub's routing protocol configuration that prevents spoke-to-spoke route advertisement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The hub router is not configured with the 'no ip split-horizon' command for EIGRP or the 'neighbor' command for OSPF, preventing spoke-to-spoke route propagation.

In a DMVPN Phase 2 network, spoke-to-spoke traffic requires that each spoke learns the remote spoke's prefix via the hub. For EIGRP, the hub must disable split horizon with 'no ip split-horizon eigrp <as>' to propagate routes learned from one spoke to other spokes. Without this, the hub advertises only its own routes, so spokes lack the necessary routing information to forward traffic directly, causing it to be sent through the hub despite working NHRP and IPsec.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The hub router is not configured with the 'no ip split-horizon' command for EIGRP or the 'neighbor' command for OSPF, preventing spoke-to-spoke route propagation.

    Why this is correct

    In DMVPN Phase 2, the hub must disable split horizon (EIGRP) or use a network type that allows route propagation (OSPF) so that spokes learn each other's subnets. Without this, spokes only have a default route via the hub, so traffic goes through the hub.

  • ✗

    The IPsec transform set on the spokes uses different encryption algorithms, preventing the spoke-to-spoke tunnel from passing traffic.

    Why it's wrong here

    IPsec transform sets are negotiated during IKE Phase 2. If the spokes used different encryption algorithms, the IPsec security associations (SAs) for spoke-to-spoke tunnels would not be established at all. Since the question explicitly states IPsec sessions are established, the transform sets must be compatible; mismatched transforms would prevent tunnel formation, not merely redirect traffic through the hub.

  • ✗

    The NHRP authentication string is mismatched between spokes, causing NHRP resolution to fail.

    Why it's wrong here

    NHRP authentication is configured on the hub and all spokes using the same string. A mismatch would cause NHRP registration and resolution requests to fail, meaning the spoke would never learn the NBMA address of the other spoke and the dynamic IPsec tunnel would never be created. Because IPsec sessions exist in this scenario, NHRP is functioning correctly; therefore, an NHRP authentication mismatch cannot be the underlying cause.

  • ✗

    The spoke routers have a static default route pointing to the hub, overriding the dynamic routes.

    Why it's wrong here

    A static default route has a prefix length of /0, which is less specific than any dynamically learned route to a remote spoke's subnet (e.g., /24). Routing decisions favor the longest prefix match, so a static default route would only be used when no more specific route exists. The real problem is that the hub's split horizon is preventing the propagation of spoke-specific routes, so the spokes have no specific routes to install—not that a default route is overriding them.

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.