Course Outline
Day 1 — BIG-IP Architecture & Platform Management
• Networking Fundamentals — OSI model (L2–L7), the role of load balancers at L4/L7; mapping IP addressing and subnetting to BIG-IP self IPs and VLANs.
• Module 1 — TMM traffic processing architecture; traffic flow from client to virtual server to pool member; device modes, administrative partitions, and role-based access control (essential for banking segregation-of-duties requirements); licensing and module provisioning (LTM, AVR).
• Module 2 — TMUI navigation and efficient GUI workflows; tmsh basics; configuration backup and restoration using UCS archives; comparison of hardware versus virtual editions and their suitability for bank datacentres.
• Practical Session (3 hours) — "Establishing Traffic Flow" — Initial setup (VLANs, self IPs, routes), creation of nodes, pools, and health monitors, construction of the first virtual server, verification of traffic to backend application servers, and execution of a UCS backup.
Day 2 — Core Load Balancing & SSL/TLS
• Networking Fundamentals — TCP/UDP handshakes and port concepts; HTTP methods, headers, status codes, and keep-alive mechanisms.
• Module 1 — Virtual server types; design of pools, nodes, and monitors; load-balancing algorithms; TCP/HTTP profiles and connection reuse; application of these concepts to internet-banking and API traffic patterns.
• Module 2 — SSL/TLS offloading and certificate management (key/certificate import, chains, and cipher policies aligned with banking security baselines); persistence methods (cookie, source-address) and their appropriate use cases; introduction to iRules with basic read-only examples (redirects, header insertion).
• Practical Session (3 hours) — Configure an HTTPS virtual server with SSL offloading for a simulated banking portal, set up cookie persistence, validate the certificate chain in a browser, implement a simple redirect iRule, and observe monitor-driven pool member failover.
Day 3 — High Availability & Operations
• Networking Fundamentals — VLANs, routing, and ARP essentials; DNS resolution flow and record types; TLS handshake review.
• Module 1 — Device Service Clustering: device trust, sync-failover groups, configuration synchronization, traffic groups, and floating IPs; failover behaviour and client experience; high availability design considerations for banking (dual-datacentre patterns, maintenance without downtime).
• Module 2 — Operations in regulated environments: local and remote logging (syslog, SNMP), AVR traffic analytics, audit logging of administrative changes, upgrade and maintenance procedures, backup strategies, and disaster-recovery basics; brief overview of automation (iControl REST) and WAF (ASM/Advanced WAF) as future topics.
• Practical Session (3 hours) — Construct an active/standby high availability pair using the two dedicated BIG-IP VEs per participant, establish device trust and configuration sync, perform a forced failover during live traffic, configure remote syslog, review audit logs, complete the final backup, and participate in the course summary and Q&A.
Lab Environment
Each participant is provided with a dedicated, isolated laboratory environment consisting of two BIG-IP Virtual Edition instances (supporting the Day 3 high availability exercise) and shared backend web servers that simulate application tiers. Access is fully browser-based via a secure Guacamole gateway, requiring only a web browser with no need for VPN clients or local software installation, thus facilitating participation from secured banking workstations. The environment is pre-configured and validated prior to Day 1, ensuring that every participant has successfully routed traffic through their own BIG-IP instance by the end of Day 1.
Requirements
No prior experience with F5 is necessary for this course.
While basic TCP/IP knowledge is beneficial, it is not a strict prerequisite. Each day begins with concise networking fundamentals (covering the OSI model, TCP/HTTP, and DNS/TLS) tailored to the day's F5 content, ensuring that teams with varying levels of experience achieve a common baseline of understanding.
Audience: Network engineers, security engineers, and application support and operations personnel within banking and financial institutions.
Testimonials (1)
communication, knowledge from experience, solve problems,