Mar 27, 2026 - For details about updated CVE-2025-53521 (BIG-IP APM vulnerability), refer to K000156741.

Forum Discussion

cirmuspts's avatar
cirmuspts
Icon for Nimbostratus rankNimbostratus
Apr 14, 2026

Recommendation for Adv. Lab

Hi Everyone,

 

I'm relatively new to F5 BIG-IP and want to improve my hands-on skills. I have a chance to build a good lab, but I'm struggling to find real-world use cases and troubleshooting scenarios.

Currently, I can only run basic tests with DVWA, but I want to simulate a complex environment.

 

Could you recommend any resources (videos, docs, or lab guides or anything can help) specifically for LTM, AWAF, DNS and APM, use-case scenarios, troubleshooting exercises, architectures etc. 

Any guidance to help me bridge the gap between basic setup and professional practice would be greatly appreciated.

 

Thanks in advance!

8 Replies

  • Hello All

    follow this same post , me too I'm relatively new to F5 world .

    Any advice or guidance is so much appreciated :-)

    Many thanks community members  !

     

    Cheers

    Antonio

  • Hey Guys,  

    IDK if this is something you are looking for, but I just posted an article on LinkedIn about my Labing Journey this weekend that might help you.  It was a fun Journey.  After you get a lab set up, It should be a quick real world set up and troubleshooting Lab.

     

    My lab is built out in GNS3 using NGINX containers and Eval License on my F5 VEs.  

     

    https://www.linkedin.com/pulse/bigip-tls-13-question-probably-cost-me-job-david-smith-rjhvc/?trackingId=lR%2BqvMjbR1qV1gF0HLA2LQ%3D%3D

     

    I am working on my 303, so I will be building labs and senarios around that also.

     

    David

  • for ltm,asm, web accel i use wackopicko as the pool member.

    https://github.com/adamdoupe/wackopicko

    for apm, add windows server vm as ad server or use azure ad, then setup single sign on.

    for gtm/dns, duplicate above to second datacenter environment.

    all above can be done in vm in laptop if you have 32 GB ram.

  • For advanced lab practice, I’d suggest checking out the official F5 community labs and training content they cover structured modules from basics to advanced scenarios and are really helpful for hands-on learning.

  • Hi all,

    Thanks for replies and advices. It looks like clouddocs or official lab guides just want to teach basics. It is very good for start point, but for growing and for more, I need real-life examples and hands-on activity.Especially troubleshoot, advanced configuration scenarios, etc.

  • Great question; you’re already on the right track by wanting to move beyond basic setups. One of the best ways to level up is to build a small “enterprise-like” lab instead of isolated tests. For example, simulate a multi-tier app (web + app + DB), then place BIG-IP LTM in front with load balancing, health monitors, and SSL offloading. After that, layer in AWAF with intentionally vulnerable apps (DVWA is good, but also try Juice Shop), and practice blocking/learning modes. For APM, set up a simple VPN or SSO scenario (even with something like Active Directory in a lab), and for DNS, try GTM-style traffic steering between two “sites” (can be VMs on your machine).

    For troubleshooting skills, deliberately break things; misconfigure health monitors, SSL profiles, or iRules; and then trace traffic using logs, tcpdump, and the BIG-IP GUI/CLI tools. F5 DevCentral is gold for real-world use cases, and their official labs (like F5 University and GitHub lab guides) are very hands-on. If you treat your lab like a mini production environment and keep asking “what would break in real life?”, you’ll close that gap much faster.

    • cirmuspts's avatar
      cirmuspts
      Icon for Nimbostratus rankNimbostratus

      Hi carlbidwell,

      First, thanks for detailed reply.

      Is there any link or section for Devcentral official labs all together? Or I need to search it manually?

  • The issue with the trial licenses never getting approved or the option for 100 dollar lab licenses being gone I think (not certain about that one but before without using a company you could buy such) makes testing F5 BIG-IP harder than it used to be :(