Course Outline
Day 1 — BIG-IP Architecture & Platform Management
• Networking refresher — Overview of the OSI model (Layers 2–7) and the role of load balancers at L4/L7; mapping IP addressing and subnetting to BIG-IP self-IPs and VLANs.
• Theory Module 1 — TMM traffic-processing architecture; tracing the traffic path from client to virtual server to pool member; device modes, administrative partitions, and role-based access control (essential for segregation of duties in banking); licensing and module provisioning (LTM, AVR).
• Theory Module 2 — Efficient navigation of the TMUI and GUI workflows; essential tmsh commands; configuration backup and restoration using UCS archives; comparison of hardware versus virtual editions and their appropriate placement in bank data centers.
• Lab (3 hours) — “Getting Traffic to Flow” — Initial configuration (VLANs, self-IPs, routes), creation of nodes, pools, and health monitors, construction of the first virtual server, verification of traffic to backend application servers, and capture of a UCS backup.
Day 2 — Core Load Balancing & SSL/TLS
• Networking refresher — TCP/UDP handshakes and port concepts; HTTP methods, headers, status codes, and keep-alive mechanisms.
• Theory Module 1 — Types of virtual servers; design of pools, nodes, and monitors; load-balancing algorithms; TCP/HTTP profiles and connection reuse; application of these concepts to internet banking and API traffic patterns.
• Theory Module 2 — SSL/TLS offloading and certificate management (importing keys/certs, certificate chains, and cipher policies aligned with banking security standards); persistence methods (cookie, source address) and their appropriate use cases; introduction to iRules with simple read-only examples such as redirects and header insertion.
• Lab (3 hours) — Build an HTTPS virtual server with SSL offloading for a simulated banking portal, configure cookie-based persistence, validate the certificate chain in a browser, implement a basic redirect iRule, and observe monitor-driven failover of pool members.
Day 3 — High Availability & Operations
• Networking refresher — Essentials of VLANs, routing, and ARP; DNS resolution flow and record types; recap of the TLS handshake.
• Theory Module 1 — Device Service Clustering: establishing device trust, sync-failover groups, configuration synchronization, traffic groups, and floating IPs; understanding failover behavior and its impact on clients; high-availability design considerations for banking, including dual-datacenter patterns and zero-downtime maintenance.
• Theory Module 2 — Operations in regulated environments: local and remote logging (syslog, SNMP), AVR traffic analytics, audit logging for administrative changes, upgrade and maintenance procedures, and disaster recovery fundamentals; brief overview of automation (iControl REST) and Web Application Firewalls (ASM/Advanced WAF) as future topics.
• Lab (3 hours) — Construct an active/standby high-availability pair using the two dedicated BIG-IP VE instances, establish device trust and configuration synchronization, execute a forced failover during live traffic, configure remote syslog, review audit logs, perform a final backup, and conclude with a course recap and Q&A.
Lab Environment
Each trainee is provided with a dedicated, isolated lab environment comprising two BIG-IP Virtual Edition instances (to support the Day 3 high-availability exercise) and shared backend web servers simulating application tiers. Access is fully browser-based through a secure Guacamole gateway, requiring only a web browser with no need for VPN clients or local software installations, which simplifies participation from restricted banking workstations. The environment is pre-configured and validated before Day 1, ensuring every trainee has working traffic through their own BIG-IP by the end of the first day.
Requirements
Prior experience with F5 is not a prerequisite for this course.
While foundational TCP/IP knowledge is beneficial, it is not strictly required. Each day begins with concise networking briefings covering the OSI model, TCP/HTTP, and DNS/TLS, which are contextualized to align with the day's F5 topics. This approach ensures that teams with diverse experience levels start on an even footing.
Audience: Network engineers, security specialists, and application support or operations personnel working within banking and financial institutions
Testimonials (1)
communication, knowledge from experience, solve problems,