hardMultiple Choice
300-410 Practice Question: DMVPN spoke-to-spoke tunnel is not forming…
DMVPN spoke-to-spoke tunnel is not forming between two spokes. Hub router R1 has the following relevant configuration: interface Tunnel0 ip address 10.0.0.1 255.255.255.0 ip nhrp network-id 1 ip nhrp map multicast dynamic ip ospf 1 area 0 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint Spoke R2 shows: show dmvpn Legend: Attrb -> S: Static, D: Dynamic, I: Incomplete Interface: Tunnel0, IPv4 NHRP Details Type:Spoke, NHRP Peers: 1 # Ent Peer NBMA Addr Peer Tunnel Add State UpDn Tm Attrb 1 192.168.1.1 10.0.0.1 UP 00:10:00 D Spoke R3 shows similar, but no spoke-to-spoke tunnel. What is the root cause?
⚠ Common exam trap
The trap is assuming that DMVPN automatically forms spoke-to-spoke tunnels once hub-spoke connectivity is established; many candidates overlook the need for NHRP redirect/shortcut commands, which are not enabled by default.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Missing ip nhrp redirect on hub and ip nhrp shortcut on spokes.
For DMVPN spoke-to-spoke tunnels to form dynamically, the hub must be configured with 'ip nhrp redirect' and each spoke with 'ip nhrp shortcut'. Without these, spokes only build tunnels to the hub (as shown by the single NHRP peer entry pointing to the hub), and traffic between spokes is routed through the hub rather than directly. The 'ip nhrp redirect' on the hub informs the originating spoke of a better path, and 'ip nhrp shortcut' on the spoke allows it to install a shortcut route to the destination spoke.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Missing ip nhrp redirect on hub and ip nhrp shortcut on spokes.
Why this is correct
Without ip nhrp redirect on the hub, the hub never tells spokes to build direct tunnels, and without ip nhrp shortcut on spokes, they keep forwarding through the hub. Both commands are required for dynamic spoke-to-spoke shortcut tunnels to form.
- ✗
OSPF network type is broadcast; change to point-to-multipoint.
Why it's wrong here
OSPF network type governs adjacency and DR election on the tunnel, not NHRP peer registration; spokes already reach the hub, so changing it cannot create spoke-to-spoke shortcuts. Point-to-multipoint is the right choice when OSPF neighbours fail to form over a partially meshed NBMA tunnel.
- ✗
IPsec is not configured; DMVPN requires encryption.
Why it's wrong here
DMVPN operates as plain GRE multipoint without IPsec; encryption is optional and unrelated to NHRP resolution, so its absence cannot stop spoke-to-spoke tunnels forming. IPsec would be required only where traffic must be encrypted or where a crypto profile is mandated by policy.
- ✗
The tunnel key is mismatched; configure tunnel key on all routers.
Why it's wrong here
A tunnel key mismatch would break the hub-spoke tunnels too, yet both spokes show their hub peer as UP, so keys already match. Tunnel keys are the correct fix when multiple GRE tunnels share the same source and destination addresses and must be distinguished.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.