Get in Touch

Course Outline

Day 1 — BIG-IP Architecture & Platform Management

•  Networking primers — OSI model (L2–L7), load balancers at L4/L7; IP addressing and subnetting mapped to BIG-IP self IPs and VLANs.

•  Theory 1 — TMM traffic-processing architecture; traffic flow client → virtual server → pool member; device modes, administrative partitions and role-based access control (relevant to segregation-of-duties requirements in banking); licensing and module provisioning (LTM, AVR).

•  Theory 2 — TMUI navigation and efficient GUI workflows; tmsh essentials; configuration backup and restore with UCS archives; overview of hardware vs virtual editions and where each fits in bank datacentres.

•  Lab (3 h) — “Get Traffic Flowing” — initial setup (VLANs, self IPs, routes), create nodes, pool and health monitor, build first virtual server, verify traffic to backend application servers, take a UCS backup.

Day 2 — Core Load Balancing & SSL/TLS

•  Networking primers — TCP/UDP handshake and port concepts; HTTP methods, headers, status codes, keep-alive.

•  Theory 1 — Virtual server types; pools, nodes and monitor design; load-balancing algorithms; TCP/HTTP profiles and connection reuse; how these apply to internet-banking and API traffic patterns.

•  Theory 2 — SSL/TLS offload and certificate management (key/cert import, chains, cipher policy — aligned with typical banking security baselines); persistence methods (cookie, source-address) and when each is appropriate; introduction to iRules with simple read-only examples (redirects, header insertion).

•  Lab (3 h) — Build an HTTPS virtual server with SSL offload for a simulated banking portal, configure cookie persistence, validate certificate chain in the browser, apply a simple redirect iRule, observe monitor-driven pool member failover.

Day 3 — High Availability & Operations

•  Networking primers — VLANs, routing and ARP essentials; DNS resolution flow and record types; TLS handshake recap.

•  Theory 1 — Device Service Clustering: device trust, sync-failover groups, config sync, traffic groups and floating IPs; failover behaviour and what clients experience; HA design considerations for banking (dual-datacentre patterns, maintenance without downtime).

•  Theory 2 — Operations for regulated environments: local and remote logging (syslog, SNMP), AVR traffic analytics, audit logging of administrative changes, upgrade and maintenance procedures, backup strategy and disaster-recovery basics; brief outlook on automation (iControl REST) and WAF (ASM/Advanced WAF) as follow-on topics.

•  Lab (3 h) — Build an active/standby HA pair from the two per-trainee BIG-IP VEs, establish device trust and config sync, execute forced failover during live traffic, configure remote syslog, review audit logs, final backup; course recap and Q&A.

Lab Environment

Each trainee receives a dedicated, isolated lab: two BIG-IP Virtual Edition instances (enabling the Day 3 HA exercise) plus shared backend web servers simulating application tiers. Access is entirely browser-based via a secured Guacamole gateway — trainees need only a web browser, with no VPN client or local software installation, simplifying participation from locked-down banking workstations. The environment is pre-built and validated before Day 1; every trainee finishes Day 1 with working traffic through their own BIG-IP.

Requirements

No prior F5 experience required.

Basic TCP/IP knowledge is helpful but not assumed , each day opens with short networking primers (OSI model, TCP/HTTP, DNS/TLS) contextualised to the day's F5 content, bringing mixed-experience teams to a common baseline.

Audience: Network engineers, security engineers, application support and operations staff in banking/financial institutions

 21 Hours

Testimonials (1)

Upcoming Courses

Related Categories