
Explore F5 201 exam preparation, outlining the exam and cert goals (Big-IP administrator or F5 CA), with a 12-section flow from basics to advanced revisits, including local traffic manager.
Designed for network engineers pursuing F5 201 exam success, with LTM and Big-IP appliance focus, GUI-based trunk tagging and VLANs, plus practice exams and demos.
Meet an international speaker and instructor with over ten years of training, certified in Cisco, F5, Arista, and Dell, who specializes in containers, security, Docker, and Kubernetes.
Outline prerequisites and exam format for F5 201, including passing F5 101, TMOS 13.1, limited resources, no dumps, and 80 multiple-choice questions.
Master F5 configuration, administration, design, and troubleshooting through 16 hours of material, with updates, Big-IP and LTM troubleshooting, practice exams, and full support to pass the 5 to 1 exam.
Explore the course flow, covering Big IP basics and revisits, LTM topics, troubleshooting, hardware and support, high availability, and creating your own lab for practice.
Explore the 5G lab topology and learn how to access our 5G device and the client.
Detail the lab setup: Intel NUC hardware, eight F5 BIG-IP devices in a cluster, VMware ESXi with Virtual Edition 13.1, optional Windows client, and testing across Chrome and Firefox.
Review the lab topology with a VIP and VLANs external and internal, using 10.0.0.0/16 and 172.16.0.0/16 networks, and a second Big-IP for high availability; load balance across three pool servers.
Manage your 5g device on a management network by accessing the F5 big-ip devices via a web browser and using bgp with 192.168.1.31 and 192.168.1.32, then remote desktop to 192.168.1.30.
Set up your F5 Big-IP lab with step-by-step instruction for standalone and active standby configurations, including downloading version 13.1 and enabling trial license keys.
Explore the basics of F5 big-ip monitoring, including statistics, network and system management modules, accessed via the configuration utility gui or cli, with options including advanced, linux and html shells.
Define tmos as the traffic management operating system that underpins F5 Big-ip, integrating modules like LTM, DNS/GTM, RSM, APM, with ai rules, ssl offload, and a full proxy architecture.
Access the F5 Big-IP appliance through management interface using https GUI or SSH, with admin for the GUI and root for SSH, and review IP configurations and port lockdown settings.
Navigate the f5 big-ip gui to access ltm and dns modules from the left pane, configure in the central pane, and use resource provisioning and the setup wizard.
Examine statistics across local traffic, pools, and interfaces using the dashboard to verify load balancing, memory, CPU, and network performance on the F5 Big-IP device.
Configure and verify connectivity across VLANs and self IP addresses in the network module, including floating and non-floating self IPs, trunks, and IPsec VPN options.
Explore the F5 big-ip system module to view and modify device configuration, manage licensing and modules, archive configurations with UCS, and configure users, SNMP, and logging.
Master resource provisioning on the F5 Big-IP by allocating CPU, memory, and disk to LTM, DNS, and APM while choosing among none, dedicated, nominal, and minimal options.
Explore the system services on a BIG-IP appliance using netstat, identify listening daemons like httpd, sshd, DNS, and NTP, and verify DNS and NTP configurations via CLI and GUI.
Explore how to access the BIG-IP CLI via SSH, console, and data interfaces, and manage admin versus root access with advanced shell and HTML shell.
Explore the advanced shell in a Linux-based BIG-IP environment, reviewing core files like big_ipconfig and big_ip_base, and managing users, profiles, VLANs, and HA settings for exam prep.
Learn to access the F5 big-ip cli via advanced shell and html shell, navigate modules, and create or modify virtual servers and pools using cli commands.
Learn to manage big ip configurations across html and advanced shells, save changes with save config, and use msh to list and delete virtual servers like http_vts and test_vts.
Generate UK view files from Big-IP devices via GUI or advanced shell, then upload to the eHealth portal, with version 13 enabling direct upload and required credentials.
Explore the basics of F5 LTM, including load balancing monitors and configuration objects such as virtual servers, pools, pool members, and nodes, plus the scripting tool and a rule.
Explore dynamic load balancing with F5 big-ip, employing list connections, list session, and predictive and observed ratio-based methods using layer four and layer seven metrics.
Configure and verify load balancing on the F5 Big-IP by creating http and ssh pools, virtual servers, and testing with browser‑based requests to observe ratio and round robin behavior.
Understand how health monitors in F5 Big-IP LTM assess pool member and node availability, using address check, service check, and content check monitors with interval and timeout settings.
Configure predefined icmp and tcp health monitors for pools and pool members, compare layer 3 versus layer 7 checks, and verify statuses using the network map and connection limits.
Explore how snat secures network traffic on a Big-IP appliance acting as a full proxy, translating client and pool member addresses and performing load balancing.
Configure snat and test http and https virtual servers, enabling auto map to translate source addresses to a floating or internal self ip, and observe load balancing among pool members.
Learn how network address translation (nat) on f5 big-ip acts as a 1-to-1, bi-directional listener, mapping a client address to a pool member, not as secure as a virtual server.
Demonstrates NAT configuration by creating a NAT list with a listener at 10.1.105 translating to 172.16.20.5, then test http, https, and SSH access without a virtual server.
Discover f5 ltm profiles, including layer seven application profiles (http, dns, ftp) and layer four tcp/udp protocols, with authentication, cookie persistence, and virtual server dependencies.
Configure a virtual server and enable an FTP profile on a F5 BIG-IP appliance. Understand command and data channels and how active FTP uses separate ports for control and data.
configure an ftp application on the f5 vip gui, add an ftp pool member, enable the system defined ftp profile, and verify access with filezilla.
Enable client ssl on the big-ip to terminate ssl at the edge, letting iRules handle data manipulation, http compression, security inspection, and centralized certificate management.
Test http and https, enable the ssl client profile, and demonstrate ssl termination offload by switching pool members to http, giving https on the client and http on the server.
Explore how persistence maintains a client's connection to a single pool member by bypassing load balancing after the first request, using source address affinity, cookie persistence, and other persistence types.
Test load balancing for http and https, then configure and verify source address affinity persistence on a Big IP virtual server, using a custom IPv4 prefix–matched persistence.
Learn cookie persistence in BIG-IP, including http cookie insert, rewrite, and passive modes. See how cookies are created, updated, and used to select pool members, with recommendation to centralize management.
Enable and verify cookie persistence for a virtual server by comparing browser-based cookies versus source address persistence, using the VIP cookie decoder to confirm cookie values and pool member continuity.
Learn how iRules enable tcl-based scripting on f5 big-ip to control traffic, select pools, redirect http to https, and log events on a virtual server.
Explore iRule configuration by testing http vs https redirects, creating pools, and using client ip and idle rules to drive load balancing across multiple pool members.
Revisit the F5 BIG-IP overview and explore advanced topics like partitions, packet filters, user roles, logging, and IOPs to deepen exam readiness.
Restrict management access to the Big-IP with admin accounts on GUI or CLI, limit SSH by IP, apply port lockdown and packet filters on data interfaces, and disable root login.
Log in to the f5 big-ip gui, configure the management port with ip address, subnet mask, and route, and set restricted ssh access to a specific ip.
Port lockdown secures unfiltered big IP traffic by controlling access to self IP addresses, with virtual server traffic unaffected and protocols and ports such as ICMP and 4353 supported.
Test port lockdown on the 5g ip device by verifying icmp reachability to internal and external self ips, then enable ssh and https for management via vlans.
Enable and configure packet filters to control network security by applying rules that accept, discard, continue, or reject traffic, including management traffic, with logging, exceptions, and protocol filtering.
Learn to configure packet filters for SSH traffic, enable rules, and create exceptions for specific self IP, virtual server, and management interface to control connections.
Learn how F5 big-ip uses a connection table to preserve ssh sessions despite port 22 filters, and how order of precedence prioritizes the connection table, filters, and virtual servers.
Test and explain order of precedence for packet filters by creating and removing SSH rules, enabling and disabling the packet filter, and observing connection behavior and the connection table.
Learn to create UCS archives for 5G devices, with encryption options and the ability to include or exclude SSL private keys, plus off-box storage for disaster recovery.
Explore UCS part 2 by locating the config directory, extracting UCS backups, and testing encrypted restoration with a passphrase in the MSH environment.
Explore using simple configuration files (sqf/sdf) to back up and restore Big-IP configurations, save and load configs via CLI or MSH, and reset to factory defaults.
Create and manage partitions to organize objects, where the common partition shares pools and virtual servers across partitions, while test and try partitions keep objects isolated.
Configure and manage partitions on the F5 big-ip, load and apply configurations, and create virtual servers within test and try partitions, noting common pools and cross-partition sharing.
Explain the difference between user accounts and user roles in F5 BIG-IP, and how roles grant permissions to resources and configuration, including creating a test user with partition access.
Demonstrates creating and testing multiple user roles (guest, operator, user manager, resource administrator, manager) across partitions, outlining permissions, access levels, and what each role can view, edit, or manage.
Explore Linux logging with syslog-ng, detailing local logging facilities for modules like LTM, GTM, APM, and Cron, and learn how to configure remote logging to syslog servers, Splunk, or ArcSight.
View and configure logs in the GUI, including system, local traffic, and audits. Use CLI to inspect /var/log and verify remote syslog setup with a Windows client.
AI apps automate creation and association of application objects, such as virtual servers, pools, and profiles, via templates, with centralized management and security-driven reconfiguration restricted to the I apps environment.
Explore configuring applications with AI apps templates to auto-create application services, virtual servers, pools, and profiles. Learn SSL offload, http/https redirection, and performance optimizations via TCP profiles and persistence.
Explore the broader LTM features beyond load balancing and learn why F5's load balancing is just a feature on the device, with many capabilities to study.
Learn how priority group activation uses pool member priorities and a less than threshold to steer load balancing, and how fallback host redirects traffic during outages for http traffic.
This lecture demonstrates how BIG-IP balances traffic across pool members and virtual servers using least connections and list methods, with IP address-only awareness and static, round-robin, and dynamic balancing options.
Nodes in F5 are IPs that can be named and are created when you add pool members; use the node default to apply health monitors and monitor total active connections.
Discover how load balancing across pool members prevents overload, with pools shared by multiple virtual servers and configurable health monitors and ramp settings.
Add and name nodes with IP or DNS, and assign ICMP health monitor, reviewing node status on the network map. Also monitor FTP and SSH connections in statistics.
Learn to configure a priority pool in local traffic with advanced options, including multiple health monitors and availability requirements, and add five pool members to test load balancing.
Configure priority group activation for a five-server pool, test failover, and implement an http fallback profile on the virtual server to redirect traffic to a public destination.
Explore virtual servers (VS) as traffic objects that load balance to pools and translate IPs and ports. Examine VS types and how profiles, iRules, persistence, and DHCP influence traffic handling.
Compare standard and performance layer four virtual servers in F5 BIG-IP, explore profiles, pools, http profile usage, i rules, and cli based setup across LTM and MSH.
Explain how standard virtual servers use full proxy to separate client and server connections while preserving end-to-end sessions. Leverage pool-based load balancing, i rules, and VLAN/LAN settings.
Configure a standard virtual server, enable ssh on port 22, adjust the pool and profiles, and verify client and server connections along with VLAN configurations.
Forwarding virtual servers route requests to a destination IP range (172.16.0.0/16) using layer 3, with no load balancing. Use a reject VTS to drop specific ports while others pass.
Configure a forwarding virtual server with a forwarding ip, test http and https access to three servers, and create a reject virtual server to block http to server two.
Assess content-based layer seven health monitors for pool members, including http/https, ftp, sip, oracle, and imap. Configure built-in and scripted monitors, and use manual rescue during maintenance.
Configure and test a custom FTP health monitor in BIG-IP, including username, password, and path and file to check, then associate it with a pool to achieve green, available status.
Configure a custom http health monitor for a three-node pool on port 80, using receive string and receive disabled string to determine online status, with reverse support.
Configure a custom http health monitor for an http pool, using receive and censoring strings to validate env.cgi, test redirects, and apply reverse and disable options.
Explore how traffic object status shows availability of virtual servers, pool members, pools, and nodes using green circle, blue square, yellow triangle, and red diamond. Observe how monitors influence status.
Explore traffic object status in the network map, including how pool members inherit the node status and how disable vs force offline affects persistence.
Explore SNAT revisits: compare automap and SNAT pool approaches, how virtual servers and pool members translate to a floating self IP, and how SNAT pools prevent port exhaustion.
Revisit SNAT configuration explains translating server-side source IPs with auto map and smart list, and resolves port exhaustion by creating a SNAT pool of multiple IPs for https traffic.
Discover how layer four and layer seven profiles optimize BIG-IP networks, focusing on TCP and UDP profiles, HTTP profiles, and techniques like the Nagle algorithm and web acceleration.
Explore http compression and caching on a big-ip virtual server, covering accept-encoding negotiation, gzip or deflate, content encoding, and ram caching of static data to reduce pool member load.
Compare four TCP profiles (LAN, one, progressive, mobile) in F5 Big-IP, detailing client-side and server-side protocol profiles, and how memory management and congestion control affect virtual server performance.
Configure and test http caching with the web acceleration profile on a virtual server, enabling http profile and ram cache, then verify caching via browser requests and hits.
Revisit SSL profiles on F5 Big-IP to terminate SSL at the device or encrypt traffic to pool members, enabling HTTP profiles, web acceleration, compression, and security inspection while managing certificates.
Revisit SSL profiles by creating a self-signed certificate, configuring a client SSL profile, testing HTTPS and HTTP profiles, and enabling server SSL for end-to-end encryption.
Review how a Big-IP virtual server uses persistence profiles to bind clients to the same pool member, with source address, cookie, SSL, destination address, and universal persistence.
Learn to configure universal persistence with http profile and url scripts, including an idle script, verify load balancing, and test persistence records using env.cgi data such as spoonman.
this lecture explains using the http request event to inspect client http headers and route requests to specific pool members, with logging, url variables, and user-agent based conditions.
Explore iRules revisit configuration by creating a script that selects a server pool based on the client user agent in http requests across different browsers.
Explore F5 hardware, including LCD/LED hardware and diagnostics statistics, and review support resources such as Ask F5, eHealth, creating support cases, and the bugtracker. Download resources for this section.
Navigate the AskF5 knowledge base at askf5.com to search configurations, procedures, and troubleshooting across F5 modules like LTM, BGP, DNS, and APM.
End user diagnostics provide reports on hardware components of the F5 Big-IP appliance; use only when advised by F5 support, update Eddie to the latest version, and view test reports.
Navigate to the F5 hardware page, access the Big-IP 6900 series platform guide, and view the LCD panel and LED indicators to troubleshoot hardware status.
Discover how to create and submit an F5 Big-IP support case, including login, serial number or registration keys, file uploads, and defining severity, impact, and availability.
Explore F5's Dev Central community to meet experts, access articles, forums, code downloads, and filter by topics like application delivery, security, cloud, and dev ops for AI templates and scripts.
Explore the F5 bug tracker to track bugs and security vulnerabilities across Big IP, Big IQ, APM, Iaps, and AGC. Access bug IDs, affected versions, CVE, statuses, and fixes.
Enable the AVR module to view system statistics and resources like CPU, memory, and disk, and export reports to PDF or CSV for CPU, memory, disk, and TCP/UDP traffic.
Log in to the eHealth portal, upload the support.csv file, and monitor five VIP health, security vulnerabilities, and traffic graphs while reviewing licenses, provisioned modules, and software versions.
Learn to manage F5 big-ip licensing by activating licenses, using registration keys, and verifying modules like LTM, HSM, DNS, and APM via the license page and CLI.
Explore high availability concepts such as device service clustering, active standby, active active solutions, device groups, and traffic groups, and learn software image upgrade and hotfix installation.
Explore high availability in F5 big-ip, including active standby and active active clusters, N plus one, with DSC synchronization and seamless session failover across up to eight devices.
Use network failover for active active or n plus one clusters with heartbeat packets. Hardware failover uses a special cable between two devices in active standby mode with proximity limits.
Prepare the DSC configuration on two BIG-IP devices with unique hostnames, verify VLANs and non-floating self IPs, synchronize clocks, archive configurations, and secure passwords for reliable high-availability and config sync.
Verify and configure a two-device F5 Big-IP high-availability pair by validating hostnames, VLANs, self IPs, and device trust, then create device groups and synchronize virtual servers.
Explore a five-device, active/standby high-availability setup with F5 big-ip, floating self IPs, and VLANs, plus forced offline and forced standby failover options.
Test and configure an active/standby setup using two BIG-IP devices and switch the active role to standby. Verify web and SSH traffic distribution across pool members and monitor traffic statistics.
Enable automated config sync across a Big-IP device group to push incremental changes to peers; note that unique network configs like self IP and VLANs do not synchronize.
Learn how traffic groups enable active-active and active-standby high availability across two IP appliances by floating objects, such as virtual addresses, floating self IPs, and virtual servers, with mac masquerading.
Create a new traffic group tg2 on the active unit, configure floating IPs and ssh/ftps addresses, then force tg2 to standby to activate on the second device.
Configure a second traffic group for an active/active Big IP pair, add self IPs and virtual addresses, enable load balancing, and verify traffic distribution across both devices.
Upgrade software image to reduce vulnerabilities, fix bugs, and enable new features. Schedule a maintenance window in high availability environments, verify compatibility, upgrade the standby first, then reboot and verify.
In a high availability environment, upgrade the standby unit, import image 14.1.2, install on boot location HD 1.2, activate, reboot, and verify the upgrade while preserving configuration.
Upload the hotfix in the hotfix tab, install and activate it on a new location during a maintenance window. Verify base image compatibility and download the matching hotfix and ISO.
Demonstrates hotfix installation on Big-IP by downgrading from 13.1.3 to 13.0.0, importing and installing the hotfix, selecting boot volume, and verifying via ssh show software stats.
Tackle troubleshooting BIG-IP and BGP concepts in the five to one exam prep, solving varied problems and exercises to strengthen your understanding of F5 technologies.
Troubleshoot management access on a Big-IP device by diagnosing self IP and management route configurations, and ensure tcp 443 is used for management traffic in system platform settings.
Troubleshoot network connectivity on an F5 Big-IP device using LACP to aggregate interfaces for redundancy and throughput. Learn network module concepts, trunk terminology, VLAN tagging, and interface media speed configuration.
Enable fallback to local authentication when the AAA server is unavailable, and configure remote TACACS+ through the system authentication page to manage external users.
Modify the existing my trunk to append interfaces 1.3 and 1.4, and configure a static route to 10.20.0.0/16 via gateway 10.10.0.254 to ensure reachability between networks.
Troubleshoot BIG-IP logs and restore configuration on a replacement RDMA device. Verify login activity in var log/secure and audit files.
Tackle troubleshooting the local traffic manager to build practical skills for the F5 201 exam, and download resources for this section to reinforce learning.
Troubleshoot BIG-IP virtual servers by precedence: specific destination IP and port, then any IP and port, and contrast forward versus reject behavior and source address /30 implications.
Troubleshoot persistence across two virtual servers by enabling match across services with source address persistence to force the same pool member for http and https requests.
Learn how the BIG-IP distributes ssh traffic across pool members using priority groups and activation rules, considering available, standby, and offline statuses to troubleshoot load balancing.
Observe a pool member move from offline to online and prevent overload with slow ramp time, while adjusting health monitors to restore availability.
Troubleshoot F5 Big-IP pool members by analyzing http codes and node monitor status to identify offline servers, then resolve by fixing the parent node and rely on pool health monitor.
Explore ssl offload with a client ssl profile that terminates encryption on BIG-IP, enabling http profile and cookie persistence, and learn when to enable server side ssl for end-to-end encryption.
Welcome to F5 201 Exam Preparation!
The F5 201 exam is the final step toward achieving the F5 Certified BIG-IP Administrator (F5-CA) certification. This exam is only available to candidates who have passed the now-retired F5 101 exam and is itself scheduled for retirement.
This course is designed to support:
Candidates still eligible to take F5 201 (TMOS Administrator v13.1.1), and
Learners preparing for the F5CAB4 and F5CAB5 exam domains, which align with the current BIG-IP Administrator certification path.
Beyond exam preparation, the course provides a strong foundation in core IT and BIG-IP concepts, helping you understand not just how to configure and administer BIG-IP, but why each component works the way it does.
F5 Certified BIG-IP Administrator is one of the top certifications in Networking and it also enables skills in Linux, Applications and Security.
This 17 hour course will help you understand the underlying technologies running in our Data Center.
This includes Networking, Linux, Security, Applications, and Proxy Services.
This course is filled with Whiteboard discussions and Config Demonstration. This will help you better understand the concepts of Networking, Applications and Security. You will also be provided Practice Exams in every section to help you ACE the actual F5 201 Exam.
I am proud to be one of the few instructors in Udemy who records themselves during the course delivery. Whether I am presenting, whiteboarding or doing lab demonstration, you will always see me. I do this so that I will be more CONNECTED to you!
Target Audience
Network Engineers
F5 Specialist/Engineers
Preparing F5 201 Exam
Preparing F5CAB4 and F5CAB5 Exams
F5 Certified BIG-IP Administrator (F5-CA)
Expectations
We will not spend lots of time on networking basics
Focus on F5 BIG-IP and LTM
Will not cover other Modules – GTM/DNS, ASM, APM
Based on F5 201 Blueprint
Includes Practice Exam that will help you ace F5 201 Exam, F5CAB4, F5CAB5