Get in Touch

Course Outline

Day 1 — BIG-IP Architecture & Platform Management

•  Networking foundations — The OSI model (Layers 2–7), the role of load balancers at L4/L7, and mapping IP addressing and subnetting to BIG-IP self IPs and VLANs.

•  Theory Module 1 — The TMM traffic-processing architecture, tracing the traffic path from client to virtual server to pool member. Covers device modes, administrative partitions, and role-based access control (addressing segregation-of-duties in banking), along with licensing and module provisioning for LTM and AVR.

•  Theory Module 2 — Efficient navigation of the TMUI and GUI workflows, essential tmsh commands, configuration backup and restore via UCS archives, and an overview of hardware versus virtual editions in the context of bank data centers.

•  Practical Lab (3 hours) — “Establishing Traffic Flow”: Initial configuration (VLANs, self IPs, routing), creation of nodes, pools, and health monitors, construction of the first virtual server, verification of traffic to backend servers, and execution of a UCS backup.

Day 2 — Core Load Balancing & SSL/TLS

•  Networking foundations — TCP/UDP handshake mechanisms and port concepts; HTTP methods, headers, status codes, and keep-alive connections.

•  Theory Module 1 — Virtual server types, design of pools/nodes/monitors, load-balancing algorithms, TCP/HTTP profiles, and connection reuse. Discussion includes the application of these concepts to internet banking and API traffic patterns.

•  Theory Module 2 — SSL/TLS offload and certificate management, including key/certificate import, chains, and cipher policies aligned with banking security baselines. Covers persistence methods (cookie, source-address) and appropriate use cases, plus an introduction to iRules with simple read-only examples like redirects and header insertion.

•  Practical Lab (3 hours) — Configuring an HTTPS virtual server with SSL offload for a simulated banking portal, setting up cookie persistence, validating the certificate chain in a browser, applying a basic redirect iRule, and observing monitor-driven pool member failover.

Day 3 — High Availability & Operations

•  Networking foundations — Essentials of VLANs, routing, and ARP; DNS resolution processes and record types; and a recap of the TLS handshake.

•  Theory Module 1 — Device Service Clustering: establishing device trust, sync-failover groups, configuration synchronization, traffic groups, and floating IPs. Analyzes failover behavior, client experience, and high-availability design considerations for banking, such as dual-datacenter patterns and maintenance without downtime.

•  Theory Module 2 — Operations in regulated environments: local and remote logging (syslog, SNMP), AVR traffic analytics, audit logging for administrative changes, upgrade/maintenance procedures, and backup/disaster recovery strategies. Includes a brief outlook on automation via iControl REST and WAF (ASM/Advanced WAF) as subsequent topics.

•  Practical Lab (3 hours) — Constructing an active/standby high-availability pair using the two assigned BIG-IP VEs, establishing device trust and configuration sync, performing forced failover under live traffic, configuring remote syslog, reviewing audit logs, and completing a final backup, followed by a course recap and Q&A.

Lab Environment

Each trainee is provided with a dedicated, isolated lab environment containing two BIG-IP Virtual Edition instances (essential for the Day 3 high-availability exercise) and shared backend web servers that simulate application tiers. Access is fully browser-based through a secured Guacamole gateway, requiring only a web browser and no VPN client or local software installation. This setup simplifies participation from secure banking workstations. The environment is pre-configured and validated prior to Day 1, ensuring every trainee has functional traffic running through their own BIG-IP by the end of the first day.

Requirements

No prior experience with F5 is necessary.

While basic TCP/IP knowledge is beneficial, it is not a prerequisite. Each day begins with concise networking primers covering the OSI model, TCP/HTTP, and DNS/TLS, tailored to align with that day's F5 content to ensure a common knowledge baseline for teams with diverse backgrounds.

Audience: Network engineers, security specialists, and application support or operations staff within banking and financial institutions.

 21 Hours

Testimonials (1)

Upcoming Courses

Related Categories