# FlexVPN Spoke to Spoke

**URL:** https://forum.networklessons.com/t/flexvpn-spoke-to-spoke/13375
**Category:** Lessons Discussion
**Created:** [January 19, 2021, 3:26pm UTC](https://forum.networklessons.com/t/flexvpn-spoke-to-spoke/13375 "2021-01-19T15:26:02Z")
**Posts on this page:** 1
**Showing post:** 3

<div class="post-metadata">

### Author: ![hlias\_giannio](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/h/ea5d25/32.png) [@hlias\_giannio](https://forum.networklessons.com/u/hlias_giannio)
#### Post date: [January 16, 2022, 12:04pm UTC](https://forum.networklessons.com/t/flexvpn-spoke-to-spoke/13375/3 "2022-01-16T12:04:57Z")

</div>

Hello,  
very nice lesson and well explained. I would just need a clarification here.

In all FlexVPN examples, the tunnel mode you are using is the default one. This means GRE. I tried the labs with a small change under the tunnel interfaces and virtual-templates:

`tunnel mode ipsec ipv4`

This leads to a direct IPSec encapsulation avoiding the GRE overhead. However, the spoke to spoke direct connectivity is not working. The NHRP redirection fails completely. Hub and spoke communication and spoke to spoke via the hub is fine though.

I am wondering if this is related to my specific software image or it is a normal behavior. Maybe NHRP is only working with GRE encapsulation like we do with classic DMVPN? Any thoughts on this would be much appreciated?

Thanks

---

_[View the full topic](https://forum.networklessons.com/t/flexvpn-spoke-to-spoke/13375)._
