FlexVPN spoke to spoke communication fails with IPSec tunnel

When implementing FlexVPN in a hub and spoke topology, it uses the Next Hop Resolution Protocol (NHRP) in order to enable spoke-to-spoke communication. NHRP will only function correctly over a GRE tunnel. A native IPSec tunnel will not tunnel NHRP communication and thus spoke to spoke communication will fail. However, communication via the hub is still possible.

https://community.cisco.com/t5/vpn/flexvpn-spoke-to-spoke-nhrp-redirect-not-working/td-p/2762514

https://forum.networklessons.com/t/flexvpn-spoke-to-spoke/13375/4?u=lagapides