nerdexam
Cisco

300-730 · Question #156

When troubleshooting FlexVPN spoke-to-spoke tunnels, what should be verified first?

The correct answer is B. The spokes have sent a resolution request. When troubleshooting FlexVPN spoke-to-spoke tunnels, confirming that the source spoke has sent an NHRP resolution request is the first step because it is the initiating action that drives the entire dynamic tunnel establishment process.

Troubleshooting VPNs

Question

When troubleshooting FlexVPN spoke-to-spoke tunnels, what should be verified first?

Options

  • ANHRP redirect is enabled on the hub.
  • BThe spokes have sent a resolution request.
  • CNHRP cache entries exist on the spoke.
  • DNHO routes exist on the spokes.

How the community answered

(40 responses)
  • A
    5% (2)
  • B
    78% (31)
  • C
    13% (5)
  • D
    5% (2)

Why each option

When troubleshooting FlexVPN spoke-to-spoke tunnels, confirming that the source spoke has sent an NHRP resolution request is the first step because it is the initiating action that drives the entire dynamic tunnel establishment process.

ANHRP redirect is enabled on the hub.

Verifying that NHRP redirect is enabled on the hub is a valid check, but the hub only sends a redirect in response to traffic it receives from the spoke, so confirming the resolution request is sent is a more foundational prior step.

BThe spokes have sent a resolution request.Correct

The spoke-to-spoke tunnel process begins only when the source spoke sends an NHRP resolution request to the hub (NHS) to discover the NBMA address of the destination spoke; if this request is not being generated, every downstream step - redirect, cache population, and direct tunnel formation - cannot occur, making it the logical first verification point.

CNHRP cache entries exist on the spoke.

NHRP cache entries on the spoke are populated only after a resolution request has been sent and a reply received from the hub, so this check belongs later in the troubleshooting sequence.

DNHO routes exist on the spokes.

NHO (Next Hop Override) routes are installed on spokes only after the spoke-to-spoke tunnel is already functional, making this a downstream verification rather than the first troubleshooting step.

Concept tested: FlexVPN NHRP resolution request spoke-to-spoke troubleshooting

Source: https://www.cisco.com/c/en/us/support/docs/security/flexvpn/116080-flexvpn-spoke-spoke.html

Topics

#FlexVPN#NHRP#spoke-to-spoke#resolution request

Community Discussion

No community discussion yet for this question.

Full 300-730 Practice