1-10 Chapter 1 - Setting Up the BIG-IP System
Lab 1.1 - Provision the BIG-IP System and
Confirm N etwork Config u rati on
Lab Objectives
• Provision your BIG-IP system with the appropriate modules for application delivery
• Verify your system has a valid hostname
• Ensure that the BIG-IP system's network settings provide appropriate administrative access
• Create a UCS archive of the BIG-IP system configuration
Estimated Time for Completion: 15 minutes
Lab Requirements
For all labs, when an “X” is listed in lab instruction steps, please
substitute your workstation number instead. For example, for workstation
1, the IP address shown as 192.168.X.31 in the lab instructions would be
entered as [Link] when carrying out the instructions. A password
specified as “f5trnX” in the instructions would be entered as f5trn1.
If lab instructions do not provide a value for a particular configuration
parameter, accept whatever the default is for that parameter.
Lab Overview
In this lab, you will start with a BIG-IP system that is already licensed, configured to sit on the network,
connected to an NTP service, and prepared for high availability (HA). You will provision your BIG-IP
system with the appropriate module(s), confirm the network configuration elements are working properly,
and take a backup of your system's configuration for safekeeping.
Lab Preparation Tasks
Verify workstation IP addresses are properly configured
Check your workstation’s network settings to ensure that it is configured with two IP addresses:
192.168.X.30/16 and 10.10.X.30/16. This will allow you to access the BIG-IP system through both the
management network and external VLAN, as well as access the applications you configure it to deliver.
1-10 Configuring F5 Advanced Web Application Firewall v14
Chapter 1 - Setting Up the BIG-IP System 1-11
Log onto Your BIG-IP System
1. Open a browser session to [Link] where “X” is your station number.
2. The BIG-IP system ships with a self-signed SSL certificate which most browsers do not
recognize. Accept the certificate (not permanently, if using Firefox) and log in with username
admin and password fStrnX, where “X” is your station number.
Provision Your BIG-IP System
3. Navigate to System » Resource Provisioning and provision the appropriate BIG-IP modules
using the specifications in the table below.
System » Resource Provisioning
Local Traffic (LTM) Nominal
Application Security Manager (ASM) Nominal
When complete, click... Submit
Your BIG-IP may produce a warning message that certain system
daemons may restart or the system may reboot, causing your session to
wait for anywhere up to several minutes. This is normal behavior when
changing provisioning settings. Click the OK button to continue.
Confirm Existing BIG-IP System Configuration
Verify VLAN configuration
4. Confirm the following VLANs are configured:
Network » VLANs : VLAN List
Name Tag Untagged Interfaces Partition/Path
external 4093 1.1 Common
internal 4094 1.2 Common
Configuring F5 Advanced Web Application Firewall v14 1-11
1-12 Chapter 1 - Setting Up the BIG-IP System
Verify self IP configuration
5. Confirm the following self IPs are configured:
Network » Self IPs
Name IP Address Netmask VLAN/Tunnel Traffic Group Port Lockdown
10.10.X.31 10.10.X.31 [Link] external traffic-group-local-only 443 and 22
10.10.X.33 10.10.X. 33 [Link] external traffic-group-1 443 and 22
172.16.X31 172.16.X.31 [Link] internal traffic-group-local-only Default
172.16X33 172.16.X.33 [Link] internal traffic-group-1 Default
Verify platform settings
6. Confirm the host name. ("X" is your station number.)
System » Platform
Host Name [Link]
Test Administrative Access to the BIG-IP System
Test HTTPS (port 443) access to VLAN external’s self IPs
On the next step, if using Firefox, uncheck the permanent exception box before creating an exception
for the certificate's validity.
7. Open a browser session to [Link] You should be successful. Accept die site’s
certificate, if and when prompted about the validity of the certificate. If using Firefox,
do not create a permanent exception. (Uncheck the permanent exception box.)
8. Log in as user admin with password fStrnX.
9. Log out and open a browser window to [Link] the floating self IP on VLAN
external. Log in as user admin with password IStrnX.
Test SSH (port 22) access to the management port
10. Using PuTTY, open an SSH session to the management port at 192.168.X.31. Make sure the
protocol is set to SSH (port 22) before connecting. Log in as root with password fStrnX.
11. Close the session.
Test SSH (port 22) access to VLAN external’s non-floating self IP
12. Using PuTTY, open an SSH session to 10.10A.31. Log in as user root with password fStrnX.
13. Close the session.
1-12 Configuring F5 Advanced Web Application Firewall v14
Chapter 1 - Setting Up the BIG-IP System 1-13
Create a UCS Archive of Your Configuration
14. Navigate to System » Archives and back up your BIG-IP system's configuration to a UCS
archive named trainX_base.ucs.
15. Download tire UCS to your workstation for safekeeping.
Classroom Network Configuration Diagram
The following diagram illustrates the classroom network configuration. Note: You may or may not use all
of the assets shown in the diagram during this course. Take some time to review the diagram and
familiarize yourself with the classroom assets.
MGMT Student Workstation X
192.168/16
Traffic Client
External
10.10/16
Student BIG-IP X Instructor BIG-IP
Internal
172.16/16
.200.200
.200.200
F5 Alert Hack-lt Active Directory Web Application Servers File Server
Dashboard Server Server Training Server (with Virtual Hosts)
Figure 6: Conceptual representation of your classroom lab environment
Configuring F5 Advanced Web Application Firewall v14 1-13