Course Outline
Day 1 — BIG-IP Architecture & Platform Management
• Networking primers covering the OSI model (L2–L7) and the role of load balancers at L4/L7; IP addressing and subnetting applied to BIG-IP self-IPs and VLANs.
• Theory 1 — TMM traffic-processing architecture; understanding traffic flow from client to virtual server to pool member; device modes, administrative partitions, and role-based access control (addressing banking segregation-of-duties needs); licensing and module provisioning (LTM, AVR).
• Theory 2 — Efficient TMUI navigation and GUI workflows; essential tmsh commands; configuration backup and restore using UCS archives; overview of hardware vs. virtual editions and their suitability for bank data centers.
• Lab (3 h) — “Get Traffic Flowing”: initial setup (VLANs, self-IPs, routes), creating nodes, pools, and health monitors, building the first virtual server, verifying traffic to backend application servers, and taking a UCS backup.
Day 2 — Core Load Balancing & SSL/TLS
• Networking primers on TCP/UDP handshakes and port concepts; HTTP methods, headers, status codes, and keep-alive connections.
• Theory 1 — Virtual server types; designing pools, nodes, and monitors; load-balancing algorithms; TCP/HTTP profiles and connection reuse; application of these concepts to internet-banking and API traffic patterns.
• Theory 2 — SSL/TLS offloading and certificate management (key/cert import, chains, cipher policies aligned with banking security baselines); persistence methods (cookie, source-address) and their appropriate use cases; introduction to iRules with simple read-only examples (redirects, header insertion).
• Lab (3 h) — Building an HTTPS virtual server with SSL offload for a simulated banking portal, configuring cookie persistence, validating the certificate chain in a browser, applying a simple redirect iRule, and observing monitor-driven pool member failover.
Day 3 — High Availability & Operations
• Networking primers on VLANs, routing, and ARP essentials; DNS resolution flow and record types; TLS handshake recap.
• Theory 1 — Device Service Clustering: device trust, sync-failover groups, config sync, traffic groups, and floating IPs; failover behavior and client experience; HA design considerations for banking, including dual-datacenter patterns and maintenance without downtime.
• Theory 2 — Operations in regulated environments: local and remote logging (syslog, SNMP), AVR traffic analytics, audit logging of administrative changes, upgrade and maintenance procedures, backup strategies, and disaster recovery basics; brief outlook on automation (iControl REST) and WAF (ASM/Advanced WAF) as follow-on topics.
• Lab (3 h) — Constructing an active/standby HA pair using the two per-trainee BIG-IP VEs, establishing device trust and config sync, executing forced failover during live traffic, configuring remote syslog, reviewing audit logs, and performing a final backup; course recap and Q&A.
Lab Environment
Each trainee receives a dedicated, isolated lab environment consisting of two BIG-IP Virtual Edition instances (enabling the Day 3 HA exercise) and shared backend web servers simulating application tiers. Access is entirely browser-based via a secure Guacamole gateway — trainees only need a web browser, with no VPN client or local software installation required, simplifying participation from locked-down banking workstations. The environment is pre-built and validated before Day 1; every trainee finishes Day 1 with working traffic through their own BIG-IP.
Requirements
No prior experience with F5 is necessary.
While basic TCP/IP knowledge is beneficial, it is not a prerequisite. Each day begins with brief networking primers (covering the OSI model, TCP/HTTP, and DNS/TLS) tailored to the day's F5 topics, ensuring mixed-experience teams start from a common knowledge baseline.
Target Audience: Network engineers, security engineers, and application support/operations staff working in banking and financial institutions
Testimonials (1)
communication, knowledge from experience, solve problems,