Course Outline
Day 1 — BIG-IP Architecture & Platform Management
• Networking primers covering the OSI model (L2–L7) and the role of load balancers at L4/L7; IP addressing and subnetting as they relate to BIG-IP self IPs and VLANs.
• Theory 1: The TMM traffic-processing architecture and the traffic flow from client to virtual server to pool member. This includes device modes, administrative partitions, and role-based access control (relevant to banking segregation-of-duties requirements), as well as licensing and module provisioning for LTM and AVR.
• Theory 2: Navigating the TMUI and optimizing GUI workflows; essential tmsh commands; configuration backup and restore using UCS archives; and an overview of hardware versus virtual editions and their suitability for bank data centres.
• Lab (3 h) — “Get Traffic Flowing”: Initial setup (VLANs, self IPs, routes), creation of nodes, pools, and health monitors, building the first virtual server, verifying traffic to backend application servers, and taking a UCS backup.
Day 2 — Core Load Balancing & SSL/TLS
• Networking primers on TCP/UDP handshakes and port concepts; HTTP methods, headers, status codes, and keep-alive mechanisms.
• Theory 1: Virtual server types; design of pools, nodes, and monitors; load-balancing algorithms; TCP/HTTP profiles and connection reuse. These concepts are applied to internet-banking and API traffic patterns.
• Theory 2: SSL/TLS offloading and certificate management, including key/cert imports, chains, and cipher policies aligned with banking security baselines. This section also covers persistence methods (cookie, source-address), their appropriate use cases, and an introduction to iRules with simple read-only examples such as redirects and header insertion.
• Lab (3 h): Building an HTTPS virtual server with SSL offloading for a simulated banking portal, configuring cookie persistence, validating the certificate chain in the browser, applying a simple redirect iRule, and observing monitor-driven pool member failover.
Day 3 — High Availability & Operations
• Networking primers on VLANs, routing, and ARP essentials; DNS resolution flows and record types; and a recap of the TLS handshake.
• Theory 1: Device Service Clustering, including device trust, sync-failover groups, configuration synchronization, traffic groups, and floating IPs. This covers failover behaviour from the client's perspective and HA design considerations for banking, such as dual-data centre patterns and maintenance without downtime.
• Theory 2: Operations in regulated environments, including local and remote logging (syslog, SNMP), AVR traffic analytics, audit logging for administrative changes, upgrade and maintenance procedures, and basic backup and disaster-recovery strategies. A brief outlook is provided on automation (iControl REST) and WAF (ASM/Advanced WAF) as potential follow-on topics.
• Lab (3 h): Building an active/standby HA pair using the two BIG-IP VE instances assigned to each trainee, establishing device trust and configuration synchronization, executing a forced failover during live traffic, configuring remote syslog, reviewing audit logs, and performing a final backup, followed by a course recap and Q&A.
Lab Environment
Each trainee receives a dedicated, isolated lab environment consisting of two BIG-IP Virtual Edition instances (necessary for the Day 3 HA exercise) and shared backend web servers that simulate application tiers. Access is entirely browser-based via a secured Guacamole gateway, meaning trainees only need a web browser and do not require a VPN client or local software installation. This setup simplifies participation, even from locked-down banking workstations. The environment is pre-built and validated before Day 1, ensuring every trainee ends Day 1 with working traffic through their own BIG-IP instance.
Requirements
No prior experience with F5 is required for this course.
While basic TCP/IP knowledge is beneficial, it is not assumed. Each day begins with concise networking primers covering the OSI model, TCP/HTTP, DNS, and TLS, contextualised to the day's F5-specific content. This approach ensures that teams with mixed experience levels start from a common baseline.
Audience: Network engineers, security engineers, and application support and operations staff within banking and financial institutions.
Testimonials (1)
communication, knowledge from experience, solve problems,