Courseiva
hardMultiple Choice

300-410 Practice Question: An engineer is troubleshooting a DMVPN phase 2…

An engineer is troubleshooting a DMVPN phase 2 deployment with IPv6 over mGRE tunnels. The spoke routers can ping the hub's tunnel IPv6 address, but cannot reach IPv6 networks behind other spokes. The engineer verifies that NHRP is configured and that the hub has a route to the spoke's internal networks. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the distinction between Phase 2 and Phase 3 DMVPN behavior, and the trap here is that candidates assume NHRP alone handles spoke-to-spoke routing, forgetting that a route pointing to the tunnel interface is required in Phase 2 for the spoke to initiate the NHRP resolution process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The spoke routers are missing a static route for the remote spoke's internal network pointing to the mGRE tunnel interface.

In a DMVPN Phase 2 deployment, spoke routers must have a route to remote spoke networks pointing to the mGRE tunnel interface. Without this static route, the spoke will not know to send traffic for the remote spoke's internal network over the tunnel, even though NHRP resolves the next-hop. The hub has a route to the spoke's internal networks, but that does not enable direct spoke-to-spoke communication without proper routing on the spokes themselves.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The spoke routers are missing a static route for the remote spoke's internal network pointing to the mGRE tunnel interface.

    Why this is correct

    Correct because without a route to the remote spoke's network via the tunnel, the spoke will send traffic to the hub, which may not forward it correctly, or the spoke may use a default route that does not use the tunnel.

  • ✗

    The NHRP authentication key is mismatched between the spokes.

    Why it's wrong here

    NHRP authentication is enforced only between each spoke and the hub during registration and resolution, not between spoke peers. In DMVPN phase 2, a spoke sends its NHRP Resolution Request to the hub, which responds with the destination spoke's NBMA address, after which the initiating spoke sends a unicast GRE packet directly to that address. The destination spoke does not validate the source spoke's NHRP authentication key because no direct NHRP packet exchange occurs between them; any mismatch between spokes is therefore irrelevant to spoke-to-spoke connectivity. If the key were mismatched between a spoke and the hub, the spoke would fail registration entirely and the problem would be much broader than a single missing route.

  • ✗

    The tunnel key is not configured on the mGRE interface.

    Why it's wrong here

    The tunnel key is an optional 8-bit identifier used to validate GRE packets on a tunnel interface; when multiple GRE tunnels share the same underlay, all routers must either use the same key or none at all. If a spoke's mGRE interface lacks the tunnel key while the hub and the remote spoke use one, GRE decapsulation would fail for all traffic, including the hub communication, which is not the reported symptom. Conversely, if no router is configured with a tunnel key, spoke-to-spoke GRE packets are encapsulated and decapsulated normally because the key merely adds a check for matching IDs. The described failure is a data-plane routing issue to a specific internal network, which a missing tunnel key cannot cause because it would break all tunnel traffic rather than a single destination.

  • ✗

    The hub is not configured with 'ip nhrp redirect' and the spokes with 'ip nhrp shortcut'.

    Why it's wrong here

    The commands 'ip nhrp redirect' (on the hub) and 'ip nhrp shortcut' (on spokes) are fundamental to DMVPN phase 3, where the hub redirects a spoke to the destination spoke's NBMA address when it sees a packet routed from one spoke to another through the hub, and the source spoke installs a dynamic NHRP shortcut entry. In DMVPN phase 2, spokes already initiate NHRP Resolution Requests to the hub for any spoke-to-spoke traffic, and the hub replies with the mapped NBMA address, so the source can establish a direct tunnel without redirect assistance. Therefore, omitting these phase 3-specific commands does not affect phase 2 operation, and the failure described (missing static route to the remote internal network) is a routing-table problem, not an NHRP forwarding-mechanism issue.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.