Learn how to set up and operate BIG-IP Access Policy Manager to protect your enterprise network and your data center using remote access methods such as SSL VPN, per-application layer 4 and reverse proxy layer 7 access methods as well as remote desktop access using Microsoft, Citrix and VMware protocols. Learn how to protect applications by adding Access Policies to BIG-IP LTM virtual servers that allow or deny user access based on a set of conditions, such as user authentication using Active Directory or RADIUS or by determining if the client is running up-to-date anti-virus or firewall software.
Discover how to configure multiple resources using the aforementioned remote access methods, to provide applications such as SSH or Windows desktop to remote servers. With multiple resources created, dynamically assign resources based on the level of trust determined by conditions such as a user’s group membership, the client IP address geolocation information, the status of applications running on the client, and other available information. See how to craft complicated policies using easy-to-learn graphical flowcharting techniques that are quick to update and simple to propagate.
Learn how to use SSO techniques to make applications more accessible and more secure using credential reuse or federated single sign-on such as SAML – including both SP and IdP use cases. Review underlying technology and discuss typical use cases. Complete hands-on labs to reinforce each new topic as well as instill confidence for using the BIG-IP system in a production environment.
Associated certification:
Exam/Test:
At the end of this course, the student will be able to:
Chapter 1: Setting Up the BIG-IP System
Chapter 2: Configuring Web Application Access
Chapter 3: Exploring the Access Policy
Chapter 4: Managing BIG-IP APM
Chapter 5: Using Authentication
Chapter 6: Understanding Assignment Agents
Chapter 7: Configuring Portal Access
Chapter 8: Configuring Network Access
Chapter 9: Deploying Macros
Chapter 10: Exploring Client-Side Checks
Chapter 11: Exploring Server-Side Checks
Chapter 12: Using Authorization
Chapter 13: Configuring App Tunnels
Chapter 14: Deploying Access Control Lists
Chapter 15: Signing On with SSO
Chapter 16: Using iRules
Chapter 17: Customizing BIG-IP APM
Chapter 18: Deploying SAML
Chapter 19: Exploring Webtops and Wizards
Chapter 20: Using BIG-IP Edge Client
Chapter 21: Configuration Project
Chapter 22: Additional Training and Certification
This course is intended for network administrators, operators, and engineers responsible for managing the normal day-to-day operation and administration of BIG-IP Access Policy Manager.
Students must complete one of the following F5 prerequisites before attending this course:
Suggested Prework
The following free Self-Directed Training (SDT) courses, although optional, are helpful for any student with limited BIG-IP administration and configuration experience:
General network technology knowledge and experience are recommended before attending any F5 Global Training Services instructor-led course, including OSI model encapsulation, routing and switching, Ethernet and ARP, TCP/IP concepts, IP addressing and subnetting, NAT and private IP addressing, NAT and private IP addressing, default gateway, network firewalls, and LAN vs. WAN.
The following course-specific knowledge and experience is suggested before attending this course:
Learn how to set up and operate BIG-IP Access Policy Manager to protect your enterprise network and your data center using remote access methods such as SSL VPN, per-application layer 4 and reverse proxy layer 7 access methods as well as remote desktop access using Microsoft, Citrix and VMware protocols. Learn how to protect applications by adding Access Policies to BIG-IP LTM virtual servers that allow or deny user access based on a set of conditions, such as user authentication using Active Directory or RADIUS or by determining if the client is running up-to-date anti-virus or firewall software.
Discover how to configure multiple resources using the aforementioned remote access methods, to provide applications such as SSH or Windows desktop to remote servers. With multiple resources created, dynamically assign resources based on the level of trust determined by conditions such as a user’s group membership, the client IP address geolocation information, the status of applications running on the client, and other available information. See how to craft complicated policies using easy-to-learn graphical flowcharting techniques that are quick to update and simple to propagate.
Learn how to use SSO techniques to make applications more accessible and more secure using credential reuse or federated single sign-on such as SAML – including both SP and IdP use cases. Review underlying technology and discuss typical use cases. Complete hands-on labs to reinforce each new topic as well as instill confidence for using the BIG-IP system in a production environment.
Associated certification:
Exam/Test:
At the end of this course, the student will be able to:
Chapter 1: Setting Up the BIG-IP System
Chapter 2: Configuring Web Application Access
Chapter 3: Exploring the Access Policy
Chapter 4: Managing BIG-IP APM
Chapter 5: Using Authentication
Chapter 6: Understanding Assignment Agents
Chapter 7: Configuring Portal Access
Chapter 8: Configuring Network Access
Chapter 9: Deploying Macros
Chapter 10: Exploring Client-Side Checks
Chapter 11: Exploring Server-Side Checks
Chapter 12: Using Authorization
Chapter 13: Configuring App Tunnels
Chapter 14: Deploying Access Control Lists
Chapter 15: Signing On with SSO
Chapter 16: Using iRules
Chapter 17: Customizing BIG-IP APM
Chapter 18: Deploying SAML
Chapter 19: Exploring Webtops and Wizards
Chapter 20: Using BIG-IP Edge Client
Chapter 21: Configuration Project
Chapter 22: Additional Training and Certification
This course is intended for network administrators, operators, and engineers responsible for managing the normal day-to-day operation and administration of BIG-IP Access Policy Manager.
Students must complete one of the following F5 prerequisites before attending this course:
Suggested Prework
The following free Self-Directed Training (SDT) courses, although optional, are helpful for any student with limited BIG-IP administration and configuration experience:
General network technology knowledge and experience are recommended before attending any F5 Global Training Services instructor-led course, including OSI model encapsulation, routing and switching, Ethernet and ARP, TCP/IP concepts, IP addressing and subnetting, NAT and private IP addressing, NAT and private IP addressing, default gateway, network firewalls, and LAN vs. WAN.
The following course-specific knowledge and experience is suggested before attending this course: