Get in Touch

Course Outline

Day 1 — BIG-IP Architecture & Platform Administration

•  Networking fundamentals — OSI model (L2–L7) and load balancers at L4/L7; mapping IP addressing and subnetting to BIG-IP self IPs and VLANs.

•  Module 1 — TMM traffic-processing architecture; traffic flow from client to virtual server to pool member; device modes, administrative partitions, and role-based access control (addressing banking segregation-of-duties requirements); licensing and module provisioning (LTM, AVR).

•  Module 2 — Navigating the TMUI and optimizing GUI workflows; tmsh basics; backing up and restoring configurations via UCS archives; comparing hardware and virtual editions and their suitability for bank data centers.

•  Lab (3 hours) — “Establishing Traffic Flow” — Initial setup (VLANs, self IPs, routes), creating nodes, pools, and health monitors, building the first virtual server, verifying backend traffic, and performing a UCS backup.

Day 2 — Core Load Balancing & SSL/TLS

•  Networking fundamentals — TCP/UDP handshakes and port concepts; HTTP methods, headers, status codes, and keep-alive mechanisms.

•  Module 1 — Types of virtual servers; designing pools, nodes, and monitors; load-balancing algorithms; TCP/HTTP profiles and connection reuse; applying these concepts to internet banking and API traffic patterns.

•  Module 2 — SSL/TLS offloading and certificate management (importing keys/certs, chains, and cipher policies aligned with banking security standards); persistence methods (cookie, source-address) and their appropriate use cases; introduction to iRules with simple read-only examples (redirects, header insertion).

•  Lab (3 hours) — Building an HTTPS virtual server with SSL offload for a simulated banking portal, configuring cookie persistence, verifying the certificate chain in the browser, applying a basic redirect iRule, and observing monitor-driven pool member failover.

Day 3 — High Availability & Operations

•  Networking fundamentals — Essentials of VLANs, routing, and ARP; DNS resolution flow and record types; recap of the TLS handshake.

•  Module 1 — Device Service Clustering: establishing device trust, sync-failover groups, config synchronization, traffic groups, and floating IPs; analyzing failover behavior and client impact; High Availability design considerations for banking (dual-data center patterns, maintenance without downtime).

•  Module 2 — Operations for regulated environments: local and remote logging (syslog, SNMP), AVR traffic analytics, audit logging of administrative changes, upgrade and maintenance procedures, backup strategies, and disaster recovery basics; a brief overview of automation (iControl REST) and WAF (ASM/Advanced WAF) as advanced topics.

•  Lab (3 hours) — Setting up an active/standby High Availability pair using the two BIG-IP VEs assigned to each trainee, establishing device trust and config sync, executing forced failover during live traffic, configuring remote syslog, reviewing audit logs, and performing a final backup; course summary and Q&A.

Lab Environment

Each trainee is provided with a dedicated, isolated lab environment featuring two BIG-IP Virtual Edition instances (for the Day 3 High Availability exercise) and shared backend web servers simulating application layers. Access is fully browser-based through a secure Guacamole gateway, requiring only a web browser and eliminating the need for VPN clients or local software installations. This simplifies participation from secured banking workstations. The environment is pre-built and validated prior to Day 1, ensuring every trainee has functional traffic running through their own BIG-IP by the end of the first day.

Requirements

No prior experience with F5 is necessary.

While basic TCP/IP knowledge is advantageous, it is not a prerequisite. To ensure all participants share a common understanding, each day begins with brief networking refreshers covering the OSI model, TCP/HTTP, and DNS/TLS, tailored to the day's F5 topics. This approach helps align teams with varying levels of experience.

Target Audience: Network engineers, security specialists, and application support/operations personnel working in banking and financial institutions.

 21 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories