Course Outline
Day 1 — BIG-IP Architecture and Platform Management
• Networking basics — OSI model (L2–L7), L4/L7 load balancers; mapping IP addressing and subnetting to BIG-IP self-IPs and VLANs.
• Theory 1 — TMM traffic processing architecture; client to virtual server to pool member traffic flow; device modes, administrative partitions, and role-based access control (key for segregation-of-duties in banking); licensing and module provisioning (LTM, AVR).
• Theory 2 — TMUI navigation and efficient GUI workflows; tmsh fundamentals; UCS archive backup and restore; overview of hardware vs. virtual editions and their application in bank data centers.
• Lab (3 h) — “Getting Traffic to Flow” — initial setup (VLANs, self-IPs, routes), creating nodes, pools, and health monitors, building the first virtual server, verifying traffic to backend servers, and taking a UCS backup.
Day 2 — Core Load Balancing and SSL/TLS
• Networking basics — TCP/UDP handshake and port concepts; HTTP methods, headers, status codes, and keep-alive.
• Theory 1 — Virtual server types; designing pools, nodes, and monitors; load balancing algorithms; TCP/HTTP profiles and connection reuse; applying these to internet banking and API traffic patterns.
• Theory 2 — SSL/TLS offloading and certificate management (importing keys/certs, chains, cipher policy aligned with banking security standards); persistence methods (cookie, source address) and their appropriate uses; introduction to iRules with simple read-only examples (redirects, header insertion).
• Lab (3 h) — Create an HTTPS virtual server with SSL offloading for a simulated banking portal, configure cookie persistence, verify the certificate chain in the browser, apply a basic redirect iRule, and observe monitor-driven pool member failover.
Day 3 — High Availability and Operations
• Networking basics — VLANs, routing, and ARP essentials; DNS resolution flow and record types; TLS handshake review.
• Theory 1 — Device Service Clustering: device trust, sync-failover groups, config sync, traffic groups, and floating IPs; failover behavior and client experience; HA design for banking (dual-data center patterns, zero-downtime maintenance).
• Theory 2 — Operations in regulated environments: local and remote logging (syslog, SNMP), AVR traffic analytics, administrative audit logging, upgrade and maintenance procedures, backup strategies, and disaster recovery basics; brief preview of automation (iControl REST) and WAF (ASM/Advanced WAF) as future topics.
• Lab (3 h) — Set up an active/standby HA pair using the two BIG-IP VEs assigned to each trainee, establish device trust and config sync, perform a forced failover during live traffic, configure remote syslog, review audit logs, and take a final backup; course summary and Q&A.
Lab Environment
Each trainee is provided with a dedicated, isolated lab environment: two BIG-IP Virtual Edition instances (to support the Day 3 HA exercise) and shared backend web servers simulating application layers. Access is fully browser-based through a secure Guacamole gateway — trainees only need a web browser, with no VPN client or local software required, making participation simple even from restricted banking workstations. The environment is pre-configured and verified before Day 1, ensuring every trainee has functioning traffic through their BIG-IP by the end of Day 1.
Requirements
No previous experience with F5 is necessary.
While basic TCP/IP knowledge is beneficial, it is not required. Each day begins with brief networking primers (OSI model, TCP/HTTP, DNS/TLS) tailored to the day's F5 topics, ensuring teams with varying levels of experience start on equal footing.
Target Audience: Network engineers, security engineers, and application support or operations staff in banking and financial services
Testimonials (1)
communication, knowledge from experience, solve problems,