Courseiva
hardMultiple Choice

300-410 Practice Question: DMVPN spoke-to-spoke tunnel is not forming…

DMVPN spoke-to-spoke tunnel is not forming between two spokes. Hub router R1 has the following relevant configuration: interface Tunnel0 ip address 10.0.0.1 255.255.255.0 ip nhrp network-id 1 ip nhrp map multicast dynamic ip ospf 1 area 0 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint Spoke R2 shows: show dmvpn Legend: Attrb -> S: Static, D: Dynamic, I: Incomplete Interface: Tunnel0, IPv4 NHRP Details Type:Spoke, NHRP Peers: 1 # Ent Peer NBMA Addr Peer Tunnel Add State UpDn Tm Attrb 1 192.168.1.1 10.0.0.1 UP 00:10:00 D Spoke R3 shows similar, but no spoke-to-spoke tunnel. What is the root cause?

⚠ Common exam trap

The trap is assuming that DMVPN automatically forms spoke-to-spoke tunnels once hub-spoke connectivity is established; many candidates overlook the need for NHRP redirect/shortcut commands, which are not enabled by default.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Missing ip nhrp redirect on hub and ip nhrp shortcut on spokes.

For DMVPN spoke-to-spoke tunnels to form dynamically, the hub must be configured with 'ip nhrp redirect' and each spoke with 'ip nhrp shortcut'. Without these, spokes only build tunnels to the hub (as shown by the single NHRP peer entry pointing to the hub), and traffic between spokes is routed through the hub rather than directly. The 'ip nhrp redirect' on the hub informs the originating spoke of a better path, and 'ip nhrp shortcut' on the spoke allows it to install a shortcut route to the destination spoke.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Missing ip nhrp redirect on hub and ip nhrp shortcut on spokes.

    Why this is correct

    Without ip nhrp redirect on the hub, the hub never tells spokes to build direct tunnels, and without ip nhrp shortcut on spokes, they keep forwarding through the hub. Both commands are required for dynamic spoke-to-spoke shortcut tunnels to form.

  • ✗

    OSPF network type is broadcast; change to point-to-multipoint.

    Why it's wrong here

    OSPF network type governs adjacency and DR election on the tunnel, not NHRP peer registration; spokes already reach the hub, so changing it cannot create spoke-to-spoke shortcuts. Point-to-multipoint is the right choice when OSPF neighbours fail to form over a partially meshed NBMA tunnel.

  • ✗

    IPsec is not configured; DMVPN requires encryption.

    Why it's wrong here

    DMVPN operates as plain GRE multipoint without IPsec; encryption is optional and unrelated to NHRP resolution, so its absence cannot stop spoke-to-spoke tunnels forming. IPsec would be required only where traffic must be encrypted or where a crypto profile is mandated by policy.

  • ✗

    The tunnel key is mismatched; configure tunnel key on all routers.

    Why it's wrong here

    A tunnel key mismatch would break the hub-spoke tunnels too, yet both spokes show their hub peer as UP, so keys already match. Tunnel keys are the correct fix when multiple GRE tunnels share the same source and destination addresses and must be distinguished.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.