Which combination of DMVPN and IPsec design choices would best support a large, geographically distributed enterprise wanting secure, scalable spoke-to-spoke connectivity with minimal per-spoke configuration overhead?
Correct Answer: DMVPN Phase 3 with NHRP for dynamic spoke-to-spoke tunnel resolution, IPsec (ESP) for encryption, and a dynamic routing protocol for reachability, configured centrally at the hub with minimal per-spoke customization
Explanation: DMVPN Phase 3 with NHRP, IPsec encryption, and dynamic routing configured centrally at the hub is the scalable, low-overhead design for large distributed spoke-to-spoke connectivity, unlike a manually configured full mesh, Phase 1's hub-only limitation, no encryption, fully manual per-spoke routing, or disabling NHRP.
Correct Answer: DMVPN Phase 3 with NHRP for dynamic spoke-to-spoke tunnel resolution, IPsec (ESP) for encryption, and a dynamic routing protocol for reachability, configured centrally at the hub with minimal per-spoke customization
Explanation: DMVPN Phase 3 with NHRP, IPsec encryption, and dynamic routing configured centrally at the hub is the scalable, low-overhead design for large distributed spoke-to-spoke connectivity, unlike a manually configured full mesh, Phase 1's hub-only limitation, no encryption, fully manual per-spoke routing, or disabling NHRP.