Get in Touch

Course Outline

Day 1 — BIG-IP Architecture & Platform Administration

Networking refreshers — OSI model (Layers 2–7), the role of load balancers at L4/L7; mapping IP addressing and subnetting to BIG-IP self IPs and VLANs.

Module 1 — TMM traffic processing architecture; understanding the traffic path from client through virtual server to pool members; device operational modes, administrative partitions, and role-based access control (essential for banking segregation of duties); licensing and module provisioning (LTM, AVR).

Module 2 — Navigating TMUI for efficient GUI workflows; tmsh command-line essentials; backing up and restoring configurations using UCS archives; comparing hardware and virtual editions and their suitability for bank data centres.

Practical Exercise (3 hours) — "Establishing Traffic Flow" — initial configuration (VLANs, self IPs, routes), creating nodes, pools, and health monitors, building the first virtual server, verifying traffic to backend servers, and performing a UCS backup.

Day 2 — Fundamental Load Balancing & SSL/TLS

Networking refreshers — TCP/UDP handshakes and port definitions; HTTP methods, headers, status codes, and keep-alive mechanisms.

Module 1 — Types of virtual servers; designing pools, nodes, and monitors; load-balancing algorithms; TCP/HTTP profiles and connection reuse; applying these concepts to internet-banking and API traffic patterns.

Module 2 — SSL/TLS offloading and certificate management (importing keys/certs, certificate chains, cipher policy aligned with banking security baselines); persistence techniques (cookie, source-address) and their appropriate use cases; introductory iRules using simple read-only examples (redirects, header insertion).

Practical Exercise (3 hours) — Creating an HTTPS virtual server with SSL offloading for a simulated banking portal, setting cookie persistence, verifying the certificate chain in a browser, applying a basic redirect iRule, and observing monitor-driven pool member failover.

Day 3 — High Availability & Operational Management

Networking refreshers — Essentials of VLANs, routing, and ARP; DNS resolution processes and record types; recap of the TLS handshake.

Module 1 — Device Service Clustering: establishing device trust, sync-failover groups, configuration synchronization, traffic groups, and floating IPs; analyzing failover behavior and client impact; high availability design strategies for banking (dual-datacentre patterns, downtime-free maintenance).

Module 2 — Operations in regulated sectors: local and remote logging (syslog, SNMP), AVR traffic analytics, audit logging of administrative actions, upgrade and maintenance protocols, backup strategies, and disaster recovery fundamentals; brief introduction to automation (iControl REST) and WAF (ASM/Advanced WAF) as future topics.

Practical Exercise (3 hours) — Configuring an active/standby HA pair using the two assigned BIG-IP VEs, establishing device trust and configuration sync, executing forced failover under live traffic, setting up remote syslog, reviewing audit logs, performing a final backup, and concluding with a course summary and Q&A.

Lab Environment

Each participant is provided with a dedicated, isolated laboratory environment comprising two BIG-IP Virtual Edition instances (to facilitate the Day 3 HA exercise) and shared backend web servers simulating application tiers. Access is fully web-based via a secured Guacamole gateway, requiring only a web browser without the need for VPN clients or local software installations. This setup simplifies participation from secured banking workstations. The environment is pre-configured and verified prior to Day 1, ensuring every trainee has functional traffic through their own BIG-IP by the end of the first day.

Requirements

No previous experience with F5 technology is necessary.

While foundational TCP/IP knowledge is beneficial, it is not a prerequisite. Each session begins with brief networking reviews—covering the OSI model, TCP/HTTP, DNS, and TLS—that are contextually linked to the day’s F5 topics, thereby aligning teams with varying skill sets to a common starting point.

Target Audience: Network engineers, security engineers, and application support or operations personnel working within banking and financial institutions.

 21 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories