Get in Touch

Course Outline

Day 1 — BIG-IP Architecture & Platform Management

Networking Refresher — Overview of the OSI model (Layers 2–7) and the role of load balancers at Layers 4/7; mapping IP addressing and subnetting to BIG-IP self IPs and VLANs.

Theory Module 1 — Understanding TMM traffic-processing architecture; traffic flow from client to virtual server to pool member; device modes, administrative partitions, and role-based access control (addressing segregation-of-duties requirements in banking); licensing and module provisioning (LTM, AVR).

Theory Module 2 — Efficient navigation and workflows in the TMUI; tmsh command-line essentials; performing configuration backups and restores using UCS archives; comparing hardware vs. virtual editions and their appropriate uses in bank data centers.

Lab (3 hours) — "Getting Traffic Flowing" — Initial setup (VLANs, self IPs, routes), creating nodes, pools, and health monitors, building the first virtual server, verifying traffic to backend application servers, and taking a UCS backup.

Day 2 — Core Load Balancing & SSL/TLS

Networking Refresher — TCP/UDP handshake and port concepts; HTTP methods, headers, status codes, and keep-alive mechanisms.

Theory Module 1 — Types of virtual servers; designing pools, nodes, and monitors; load-balancing algorithms; TCP/HTTP profiles and connection reuse; applying these concepts to internet-banking and API traffic patterns.

Theory Module 2 — SSL/TLS offload and certificate management (importing keys/certs, managing chains, and cipher policies aligned with banking security baselines); persistence methods (cookie-based, source-address) and their appropriate use cases; introduction to iRules with simple read-only examples such as redirects and header insertion.

Lab (3 hours) — Creating an HTTPS virtual server with SSL offload for a simulated banking portal, configuring cookie persistence, validating the certificate chain in the browser, applying a simple redirect iRule, and observing monitor-driven pool member failover.

Day 3 — High Availability & Operations

Networking Refresher — Essentials of VLANs, routing, and ARP; DNS resolution flow and record types; recap of the TLS handshake.

Theory Module 1 — Device Service Clustering: establishing device trust, sync-failover groups, configuration synchronization, traffic groups, and floating IPs; understanding failover behavior and its impact on clients; HA design considerations for banking, including dual-data center patterns and maintenance without downtime.

Theory Module 2 — Operations in regulated environments: local and remote logging (syslog, SNMP), AVR traffic analytics, audit logging of administrative changes, upgrade and maintenance procedures, backup strategies, and disaster recovery fundamentals; brief overview of automation via iControl REST and WAF (ASM/Advanced WAF) as advanced topics.

Lab (3 hours) — Building an active/standby HA pair using the two per-trainee BIG-IP VE instances, establishing device trust and config sync, executing forced failover during live traffic, configuring remote syslog, reviewing audit logs, performing a final backup; course summary and Q&A.

Lab Environment

Each trainee is provided with a dedicated, isolated lab environment containing two BIG-IP Virtual Edition instances (for the Day 3 HA exercise) along with shared backend web servers that simulate application tiers. Access is fully browser-based via a secure Guacamole gateway, meaning trainees only need a web browser with no requirement for VPN clients or local software installations. This setup simplifies participation from locked-down banking workstations. The environment is pre-built and validated prior to Day 1, ensuring every trainee completes Day 1 with working traffic through their own BIG-IP instance.

Requirements

No prior experience with F5 products is necessary.

While basic TCP/IP knowledge is beneficial, it is not a strict prerequisite. Each day begins with concise networking refresher sessions covering the OSI model, TCP/HTTP, DNS, and TLS, tailored to align with that day's F5 topics. This approach ensures that teams with varying levels of experience are brought to a common baseline.

Target Audience: Network engineers, security specialists, and application support/operations staff within banking and financial institutions

 21 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories