Get in Touch

Course Outline

Day 1 — BIG-IP Architecture & Platform Management

Networking foundations — OSI model (Layers 2–7), the role of load balancers at Layers 4 and 7; mapping IP addressing and subnetting to BIG-IP self IPs and VLANs.

Theory 1 — TMM traffic processing architecture; traffic flow from client to virtual server to pool member; device modes, administrative partitions, and role-based access control (aligned with banking segregation-of-duties requirements); licensing and module provisioning for LTM and AVR.

Theory 2 — Efficient navigation of the TMUI and GUI workflows; essential tmsh commands; performing configuration backups and restores with UCS archives; overview of hardware versus virtual editions and their appropriate placement in bank data centers.

Lab (3 hours) — “Get Traffic Flowing” — initial configuration including VLANs, self IPs, and routes; creation of nodes, pools, and health monitors; building a first virtual server; verifying traffic to backend application servers; completing a UCS backup.

Day 2 — Core Load Balancing & SSL/TLS

Networking foundations — TCP/UDP handshake mechanisms and port concepts; HTTP methods, headers, status codes, and keep-alive connections.

Theory 1 — Types of virtual servers; design of pools, nodes, and monitors; load balancing algorithms; TCP/HTTP profiles and connection reuse; application of these concepts to internet banking and API traffic patterns.

Theory 2 — SSL/TLS offload and certificate management (importing keys/certs, chains, and cipher policies aligned with banking security baselines); persistence methods (cookie-based and source-address based) and their appropriate use cases; introduction to iRules with simple read-only examples such as redirects and header insertion.

Lab (3 hours) — Construct an HTTPS virtual server with SSL offload for a simulated banking portal; configure cookie persistence; validate the certificate chain in the browser; apply a simple redirect iRule; observe monitor-driven pool member failover.

Day 3 — High Availability & Operations

Networking foundations — Essentials of VLANs, routing, and ARP; DNS resolution flow and record types; review of the TLS handshake.

Theory 1 — Device Service Clustering: establishing device trust, sync-failover groups, configuration synchronization, traffic groups, and floating IPs; understanding failover behavior and client experience; high availability design considerations for banking, including dual-datacenter patterns and downtime-free maintenance.

Theory 2 — Operations in regulated environments: local and remote logging (syslog, SNMP), AVR traffic analytics, audit logging of administrative changes, upgrade and maintenance procedures, backup strategies, and disaster recovery basics; brief overview of automation (iControl REST) and WAF (ASM/Advanced WAF) as advanced topics.

Lab (3 hours) — Set up an active/standby high availability pair using two per-trainee BIG-IP VEs; establish device trust and configuration synchronization; execute forced failover during live traffic; configure remote syslog; review audit logs; perform a final backup; conclude with a course recap and Q&A.

Lab Environment

Each trainee is provided with a dedicated, isolated lab environment containing two BIG-IP Virtual Edition instances (to support the Day 3 high availability exercise) and shared backend web servers that simulate application tiers. Access is fully browser-based through a secure Guacamole gateway, meaning trainees only need a web browser—no VPN client or local software installation is required. This setup simplifies participation from restricted banking workstations. The environment is pre-configured and validated prior to Day 1, ensuring that every trainee has functional traffic flowing through their own BIG-IP instance by the end of the first day.

Requirements

Previous F5 experience is not necessary for this course.

While basic TCP/IP knowledge is beneficial, it is not a strict prerequisite. Each day begins with concise networking primers covering the OSI model, TCP/HTTP, DNS, and TLS, tailored to the specific F5 content of the day. This approach ensures that teams with mixed experience levels reach a common technical baseline.

Audience: Network engineers, security engineers, and application support and operations staff within banking and financial institutions

 21 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories