<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="20054" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/f5networks-trg-big-awf-cfg" lastchanged="2026-05-12T08:57:34+02:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Configuring F5 Advanced WAF (previously licensed as ASM)</title><productcode>TRG-BIG-AWF-CFG</productcode><vendorcode>F5</vendorcode><vendorname>F5 Networks</vendorname><fullproductcode>F5-TRG-BIG-AWF-CFG</fullproductcode><version>15.1</version><objective>&lt;ul&gt;
&lt;li&gt;Students should be able to:&lt;/li&gt;&lt;li&gt;Describe the role of the BIG-IP system as a full proxy device in an application delivery network&lt;/li&gt;&lt;li&gt;Provision the F5 Advanced Web Application Firewall&lt;/li&gt;&lt;li&gt;Define a web application firewall&lt;/li&gt;&lt;li&gt;Describe how F5 Advanced Web Application Firewall protects a web application by securing file types, URLs, and parameters&lt;/li&gt;&lt;li&gt;Deploy F5 Advanced Web Application Firewall using the Rapid Deployment template (and other templates) and define the security checks included in each&lt;/li&gt;&lt;li&gt;Define learn, alarm, and block settings as they pertain to configuring F5 Advanced Web Application Firewall&lt;/li&gt;&lt;li&gt;Define attack signatures and explain why attack signature staging is important&lt;/li&gt;&lt;li&gt;Deploy Threat Campaigns to secure against CVE threats&lt;/li&gt;&lt;li&gt;Contrast positive and negative security policy implementation and explain benefits of each&lt;/li&gt;&lt;li&gt;Configure security processing at the parameter level of a web application&lt;/li&gt;&lt;li&gt;Deploy F5 Advanced Web Application Firewall using the Automatic Policy Builder&lt;/li&gt;&lt;li&gt;Tune a policy manually or allow automatic policy building&lt;/li&gt;&lt;li&gt;Integrate third party application vulnerability scanner output into a security policy&lt;/li&gt;&lt;li&gt;Configure login enforcement for flow control&lt;/li&gt;&lt;li&gt;Mitigate credential stuffing&lt;/li&gt;&lt;li&gt;Configure protection against brute force attacks&lt;/li&gt;&lt;li&gt;Deploy Advanced Bot Defense against web scrapers, all known bots, and other automated agents&lt;/li&gt;&lt;li&gt;Deploy DataSafe to secure client-side data&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;The following free Self-Directed Training (SDT) courses, although optional, are helpful for any student with limited BIG-IP administration and configuration experience:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Getting Started with BIG-IP&lt;/li&gt;&lt;li&gt;Getting Started with Local Traffic Manager (LTM)&lt;/li&gt;&lt;li&gt;Getting Started with F5 Advanced WAF&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;General network technology knowledge and experience are recommended before attending any F5 Global Training Services instructor-led course, including OSI model encapsulation, routing and switching, Ethernet and ARP, TCP/IP concepts, IP addressing and subnetting, NAT and private IP addressing, NAT and private IP addressing, default gateway, network firewalls, and LAN vs. WAN.&lt;/p&gt;</essentials><contents>&lt;ul&gt;
&lt;li&gt;Introducing the BIG-IP System&lt;/li&gt;&lt;li&gt;Traffic Processing with BIG-IP&lt;/li&gt;&lt;li&gt;Overview of Web Application Processing&lt;/li&gt;&lt;li&gt;Overview of Web Application Vulnerabilities&lt;/li&gt;&lt;li&gt;Security Policy Deployments: Concepts and Terminology&lt;/li&gt;&lt;li&gt;Policy Tuning and Violations&lt;/li&gt;&lt;li&gt;Using Attack Signatures and Threat Campaigns&lt;/li&gt;&lt;li&gt;Positive Security Policy Building&lt;/li&gt;&lt;li&gt;Securing Cookies and other Header Topics&lt;/li&gt;&lt;li&gt;Visual Reporting and Logging&lt;/li&gt;&lt;li&gt;Lab Project 1&lt;/li&gt;&lt;li&gt;Advanced Parameter Handling&lt;/li&gt;&lt;li&gt;Automatic Policy Building&lt;/li&gt;&lt;li&gt;Integrating with Web Application Vulnerability Scanners&lt;/li&gt;&lt;li&gt;Deploying Layered Policies&lt;/li&gt;&lt;li&gt;Login Enforcement and Brute Force Mitigation&lt;/li&gt;&lt;li&gt;Reconnaissance with Session Tracking&lt;/li&gt;&lt;li&gt;Layer 7 Denial of Service Mitigation&lt;/li&gt;&lt;li&gt;Advanced Bot Defense&lt;/li&gt;&lt;li&gt;Final Projects&lt;/li&gt;&lt;/ul&gt;</contents><outline>&lt;h5&gt;Chapter 1: Introducing the BIG-IP System&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Initially Setting Up the BIG-IP System&lt;/li&gt;&lt;li&gt;Archiving the BIG-IP Configuration&lt;/li&gt;&lt;li&gt;Leveraging F5 Support Resources and Tools&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 2: Traffic Processing with BIG-IP&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Identifying BIG-IP Traffic Processing Objects&lt;/li&gt;&lt;li&gt;Understanding Profiles&lt;/li&gt;&lt;li&gt;Overview of Local Traffic Policies&lt;/li&gt;&lt;li&gt;Visualizing the HTTP Request Flow&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 3: Overview of Web Application Processing&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Web Application Firewall: Layer 7 Protection&lt;/li&gt;&lt;li&gt;Layer 7 Security Checks&lt;/li&gt;&lt;li&gt;Overview of Web Communication Elements&lt;/li&gt;&lt;li&gt;Overview of the HTTP Request Structure&lt;/li&gt;&lt;li&gt;Examining HTTP Responses&lt;/li&gt;&lt;li&gt;How F5 Advanced WAF Parses File Types, URLs, and Parameters&lt;/li&gt;&lt;li&gt;Using the Fiddler HTTP Proxy&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 4: Overview of Web Application Vulnerabilities&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;A Taxonomy of Attacks: The Threat Landscape&lt;/li&gt;&lt;li&gt;Common Exploits Against Web Applications&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 5: Security Policy Deployments: Concepts and Terminology&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Defining Learning&lt;/li&gt;&lt;li&gt;Comparing Positive and Negative Security Models&lt;/li&gt;&lt;li&gt;The Deployment Workflow&lt;/li&gt;&lt;li&gt;Assigning Policy to Virtual Server&lt;/li&gt;&lt;li&gt;Deployment Workflow: Using Advanced Settings&lt;/li&gt;&lt;li&gt;Configure Server Technologies&lt;/li&gt;&lt;li&gt;Defining Attack Signatures&lt;/li&gt;&lt;li&gt;Viewing Requests&lt;/li&gt;&lt;li&gt;Security Checks Offered by Rapid Deployment&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 6: Policy Tuning and Violations&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Post-Deployment Traffic Processing&lt;/li&gt;&lt;li&gt;How Violations are Categorized&lt;/li&gt;&lt;li&gt;Violation Rating: A Threat Scale&lt;/li&gt;&lt;li&gt;Defining Staging and Enforcement&lt;/li&gt;&lt;li&gt;Defining Enforcement Mode&lt;/li&gt;&lt;li&gt;Defining the Enforcement Readiness Period&lt;/li&gt;&lt;li&gt;Reviewing the Definition of Learning&lt;/li&gt;&lt;li&gt;Defining Learning Suggestions&lt;/li&gt;&lt;li&gt;Choosing Automatic or Manual Learning&lt;/li&gt;&lt;li&gt;Defining the Learn, Alarm and Block Settings&lt;/li&gt;&lt;li&gt;Interpreting the Enforcement Readiness Summary&lt;/li&gt;&lt;li&gt;Configuring the Blocking Response Page&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 7: Using Attack Signatures and Threat Campaigns&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Defining Attack Signatures&lt;/li&gt;&lt;li&gt;Attack Signature Basics&lt;/li&gt;&lt;li&gt;Creating User-Defined Attack Signatures&lt;/li&gt;&lt;li&gt;Defining Simple and Advanced Edit Modes&lt;/li&gt;&lt;li&gt;Defining Attack Signature Sets&lt;/li&gt;&lt;li&gt;Defining Attack Signature Pools&lt;/li&gt;&lt;li&gt;Understanding Attack Signatures and Staging&lt;/li&gt;&lt;li&gt;Updating Attack Signatures&lt;/li&gt;&lt;li&gt;Defining Threat Campaigns&lt;/li&gt;&lt;li&gt;Deploying Threat Campaigns&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 8: Positive Security Policy Building&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Defining and Learning Security Policy Components&lt;/li&gt;&lt;li&gt;Defining the Wildcard&lt;/li&gt;&lt;li&gt;Defining the Entity Lifecycle&lt;/li&gt;&lt;li&gt;Choosing the Learning Scheme&lt;/li&gt;&lt;li&gt;How to Learn: Never (Wildcard Only)&lt;/li&gt;&lt;li&gt;How to Learn: Always&lt;/li&gt;&lt;li&gt;How to Learn: Selective&lt;/li&gt;&lt;li&gt;Reviewing the Enforcement Readiness Period: Entities&lt;/li&gt;&lt;li&gt;Viewing Learning Suggestions and Staging Status&lt;/li&gt;&lt;li&gt;Defining the Learning Score&lt;/li&gt;&lt;li&gt;Defining Trusted and Untrusted IP Addresses&lt;/li&gt;&lt;li&gt;How to Learn: Compact&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 9: Securing Cookies and other Header Topics&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;The Purpose of F5 Advanced WAF Cookies&lt;/li&gt;&lt;li&gt;Defining Allowed and Enforced Cookies&lt;/li&gt;&lt;li&gt;Securing HTTP headers&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 10: Visual Reporting and Logging&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Viewing Application Security Summary Data&lt;/li&gt;&lt;li&gt;Reporting: Build Your Own View&lt;/li&gt;&lt;li&gt;Reporting: Chart based on filters&lt;/li&gt;&lt;li&gt;Brute Force and Web Scraping Statistics&lt;/li&gt;&lt;li&gt;Viewing Resource Reports&lt;/li&gt;&lt;li&gt;PCI Compliance: PCI-DSS 3.0&lt;/li&gt;&lt;li&gt;Analyzing Requests&lt;/li&gt;&lt;li&gt;Local Logging Facilities and Destinations&lt;/li&gt;&lt;li&gt;Viewing Logs in the Configuration Utility&lt;/li&gt;&lt;li&gt;Defining the Logging Profile&lt;/li&gt;&lt;li&gt;Configuring Response Logging&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 11: Lab Project 1&lt;/h5&gt;&lt;h5&gt;Chapter 12: Advanced Parameter Handling&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Defining Parameter Types&lt;/li&gt;&lt;li&gt;Defining Static Parameters&lt;/li&gt;&lt;li&gt;Defining Dynamic Parameters&lt;/li&gt;&lt;li&gt;Defining Parameter Levels&lt;/li&gt;&lt;li&gt;Other Parameter Considerations&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 13: Automatic Policy Building&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Defining Templates Which Automate Learning&lt;/li&gt;&lt;li&gt;Defining Policy Loosening&lt;/li&gt;&lt;li&gt;Defining Policy Tightening&lt;/li&gt;&lt;li&gt;Defining Learning Speed: Traffic Sampling&lt;/li&gt;&lt;li&gt;Defining Track Site Changes&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 14: Integrating with Web Application Vulnerability Scanners&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Integrating Scanner Output&lt;/li&gt;&lt;li&gt;Importing Vulnerabilities&lt;/li&gt;&lt;li&gt;Resolving Vulnerabilities&lt;/li&gt;&lt;li&gt;Using the Generic XML Scanner XSD file&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 15: Deploying Layered Policies&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Defining a Parent Policy&lt;/li&gt;&lt;li&gt;Defining Inheritance&lt;/li&gt;&lt;li&gt;Parent Policy Deployment Use Cases&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 16: Login Enforcement and Brute Force Mitigation&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Defining Login Pages for Flow Control&lt;/li&gt;&lt;li&gt;Configuring Automatic Detection of Login Pages&lt;/li&gt;&lt;li&gt;Defining Brute Force Attacks&lt;/li&gt;&lt;li&gt;Brute Force Protection Configuration&lt;/li&gt;&lt;li&gt;Source-Based Brute Force Mitigations&lt;/li&gt;&lt;li&gt;Defining Credential Stuffing&lt;/li&gt;&lt;li&gt;Mitigating Credential Stuffing&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 17: Reconnaissance with Session Tracking&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Defining Session Tracking&lt;/li&gt;&lt;li&gt;Configuring Actions Upon Violation Detection&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 18: Layer 7 Denial of Service Mitigation&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Defining Denial of Service Attacks&lt;/li&gt;&lt;li&gt;Defining the DoS Protection Profile&lt;/li&gt;&lt;li&gt;Overview of TPS-based DoS Protection&lt;/li&gt;&lt;li&gt;Creating a DoS Logging Profile&lt;/li&gt;&lt;li&gt;Applying TPS Mitigations&lt;/li&gt;&lt;li&gt;Defining Behavioral and Stress-Based Detection&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 19: Advanced Bot Defense&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Classifying Clients with the Bot Defense Profile&lt;/li&gt;&lt;li&gt;Defining Bot Signatures&lt;/li&gt;&lt;li&gt;Defining F5 Fingerprinting&lt;/li&gt;&lt;li&gt;Defining Bot Defense Profile Templates&lt;/li&gt;&lt;li&gt;Defining Microservices protection&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Chapter 20: Final Projects&lt;/h5&gt;</outline><objective_plain>- Students should be able to:
- Describe the role of the BIG-IP system as a full proxy device in an application delivery network
- Provision the F5 Advanced Web Application Firewall
- Define a web application firewall
- Describe how F5 Advanced Web Application Firewall protects a web application by securing file types, URLs, and parameters
- Deploy F5 Advanced Web Application Firewall using the Rapid Deployment template (and other templates) and define the security checks included in each
- Define learn, alarm, and block settings as they pertain to configuring F5 Advanced Web Application Firewall
- Define attack signatures and explain why attack signature staging is important
- Deploy Threat Campaigns to secure against CVE threats
- Contrast positive and negative security policy implementation and explain benefits of each
- Configure security processing at the parameter level of a web application
- Deploy F5 Advanced Web Application Firewall using the Automatic Policy Builder
- Tune a policy manually or allow automatic policy building
- Integrate third party application vulnerability scanner output into a security policy
- Configure login enforcement for flow control
- Mitigate credential stuffing
- Configure protection against brute force attacks
- Deploy Advanced Bot Defense against web scrapers, all known bots, and other automated agents
- Deploy DataSafe to secure client-side data</objective_plain><essentials_plain>The following free Self-Directed Training (SDT) courses, although optional, are helpful for any student with limited BIG-IP administration and configuration experience:


- Getting Started with BIG-IP
- Getting Started with Local Traffic Manager (LTM)
- Getting Started with F5 Advanced WAF
General network technology knowledge and experience are recommended before attending any F5 Global Training Services instructor-led course, including OSI model encapsulation, routing and switching, Ethernet and ARP, TCP/IP concepts, IP addressing and subnetting, NAT and private IP addressing, NAT and private IP addressing, default gateway, network firewalls, and LAN vs. WAN.</essentials_plain><contents_plain>- Introducing the BIG-IP System
- Traffic Processing with BIG-IP
- Overview of Web Application Processing
- Overview of Web Application Vulnerabilities
- Security Policy Deployments: Concepts and Terminology
- Policy Tuning and Violations
- Using Attack Signatures and Threat Campaigns
- Positive Security Policy Building
- Securing Cookies and other Header Topics
- Visual Reporting and Logging
- Lab Project 1
- Advanced Parameter Handling
- Automatic Policy Building
- Integrating with Web Application Vulnerability Scanners
- Deploying Layered Policies
- Login Enforcement and Brute Force Mitigation
- Reconnaissance with Session Tracking
- Layer 7 Denial of Service Mitigation
- Advanced Bot Defense
- Final Projects</contents_plain><outline_plain>Chapter 1: Introducing the BIG-IP System


- Initially Setting Up the BIG-IP System
- Archiving the BIG-IP Configuration
- Leveraging F5 Support Resources and Tools
Chapter 2: Traffic Processing with BIG-IP


- Identifying BIG-IP Traffic Processing Objects
- Understanding Profiles
- Overview of Local Traffic Policies
- Visualizing the HTTP Request Flow
Chapter 3: Overview of Web Application Processing


- Web Application Firewall: Layer 7 Protection
- Layer 7 Security Checks
- Overview of Web Communication Elements
- Overview of the HTTP Request Structure
- Examining HTTP Responses
- How F5 Advanced WAF Parses File Types, URLs, and Parameters
- Using the Fiddler HTTP Proxy
Chapter 4: Overview of Web Application Vulnerabilities


- A Taxonomy of Attacks: The Threat Landscape
- Common Exploits Against Web Applications
Chapter 5: Security Policy Deployments: Concepts and Terminology


- Defining Learning
- Comparing Positive and Negative Security Models
- The Deployment Workflow
- Assigning Policy to Virtual Server
- Deployment Workflow: Using Advanced Settings
- Configure Server Technologies
- Defining Attack Signatures
- Viewing Requests
- Security Checks Offered by Rapid Deployment
Chapter 6: Policy Tuning and Violations


- Post-Deployment Traffic Processing
- How Violations are Categorized
- Violation Rating: A Threat Scale
- Defining Staging and Enforcement
- Defining Enforcement Mode
- Defining the Enforcement Readiness Period
- Reviewing the Definition of Learning
- Defining Learning Suggestions
- Choosing Automatic or Manual Learning
- Defining the Learn, Alarm and Block Settings
- Interpreting the Enforcement Readiness Summary
- Configuring the Blocking Response Page
Chapter 7: Using Attack Signatures and Threat Campaigns


- Defining Attack Signatures
- Attack Signature Basics
- Creating User-Defined Attack Signatures
- Defining Simple and Advanced Edit Modes
- Defining Attack Signature Sets
- Defining Attack Signature Pools
- Understanding Attack Signatures and Staging
- Updating Attack Signatures
- Defining Threat Campaigns
- Deploying Threat Campaigns
Chapter 8: Positive Security Policy Building


- Defining and Learning Security Policy Components
- Defining the Wildcard
- Defining the Entity Lifecycle
- Choosing the Learning Scheme
- How to Learn: Never (Wildcard Only)
- How to Learn: Always
- How to Learn: Selective
- Reviewing the Enforcement Readiness Period: Entities
- Viewing Learning Suggestions and Staging Status
- Defining the Learning Score
- Defining Trusted and Untrusted IP Addresses
- How to Learn: Compact
Chapter 9: Securing Cookies and other Header Topics


- The Purpose of F5 Advanced WAF Cookies
- Defining Allowed and Enforced Cookies
- Securing HTTP headers
Chapter 10: Visual Reporting and Logging


- Viewing Application Security Summary Data
- Reporting: Build Your Own View
- Reporting: Chart based on filters
- Brute Force and Web Scraping Statistics
- Viewing Resource Reports
- PCI Compliance: PCI-DSS 3.0
- Analyzing Requests
- Local Logging Facilities and Destinations
- Viewing Logs in the Configuration Utility
- Defining the Logging Profile
- Configuring Response Logging
Chapter 11: Lab Project 1

Chapter 12: Advanced Parameter Handling


- Defining Parameter Types
- Defining Static Parameters
- Defining Dynamic Parameters
- Defining Parameter Levels
- Other Parameter Considerations
Chapter 13: Automatic Policy Building


- Defining Templates Which Automate Learning
- Defining Policy Loosening
- Defining Policy Tightening
- Defining Learning Speed: Traffic Sampling
- Defining Track Site Changes
Chapter 14: Integrating with Web Application Vulnerability Scanners


- Integrating Scanner Output
- Importing Vulnerabilities
- Resolving Vulnerabilities
- Using the Generic XML Scanner XSD file
Chapter 15: Deploying Layered Policies


- Defining a Parent Policy
- Defining Inheritance
- Parent Policy Deployment Use Cases
Chapter 16: Login Enforcement and Brute Force Mitigation


- Defining Login Pages for Flow Control
- Configuring Automatic Detection of Login Pages
- Defining Brute Force Attacks
- Brute Force Protection Configuration
- Source-Based Brute Force Mitigations
- Defining Credential Stuffing
- Mitigating Credential Stuffing
Chapter 17: Reconnaissance with Session Tracking


- Defining Session Tracking
- Configuring Actions Upon Violation Detection
Chapter 18: Layer 7 Denial of Service Mitigation


- Defining Denial of Service Attacks
- Defining the DoS Protection Profile
- Overview of TPS-based DoS Protection
- Creating a DoS Logging Profile
- Applying TPS Mitigations
- Defining Behavioral and Stress-Based Detection
Chapter 19: Advanced Bot Defense


- Classifying Clients with the Bot Defense Profile
- Defining Bot Signatures
- Defining F5 Fingerprinting
- Defining Bot Defense Profile Templates
- Defining Microservices protection
Chapter 20: Final Projects</outline_plain><duration unit="d" days="4">4 days</duration><pricelist><price country="NL" currency="EUR">3800.00</price><price country="BE" currency="EUR">3800.00</price><price country="IT" currency="EUR">3800.00</price><price country="GB" currency="GBP">3280.00</price><price country="FR" currency="EUR">3800.00</price><price country="CH" currency="USD">5280.00</price><price country="AT" currency="USD">5280.00</price><price country="DE" currency="EUR">3800.00</price></pricelist><miles/></course>