Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
References
(Ref:1) Kozierok, Charles M. 2005. The TCP/IP Guide. No Starch Press, Inc. San Francisco,
CA. 94103. ISBN 1-59327-047-X
(Ref:2) Liu, Cricket and Albitz, Paul. 2006. DNS and BIND, Fifth Edition. O’Reilly Media, Inc.
Sebastopol, CA. 95472. ISBN 978-0-596-10057-5
Manual: BIG-IP Global Traffic Manager: Implementations
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-implementations-11-3-
0.html?sr=28646530
Manual: BIG-IP Global Traffic Manager: Concepts
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-concepts-11-3-0.html
Manual: Traffic Management Shell (tmsh) Reference Guide version 11.3.0 (MAN-0306-04)
http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/bigip-tmsh-11-3-
0.html?sr=28675254
Configuring BIG-IP GTM v11 Global Traffic Manager. March 2013 v11.3.0. Edition. F5 Networks
Training Course. (Configuring GTM: Module X)
Section 1, Concepts
1.01 Identify resource record types and their purpose including DNSSEC record
types.
Example: Identify resource record types and their purpose.
Example: Identify DNSSEC purpose and GTM implementation
• Ref: 1, p. 892, Record Types.
• http://en.wikipedia.org/wiki/List_of_DNS_record_types
• Manual Chapter: BIG-IP DNS Services: Implementations> Configuring DNSSEC
http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/bigip-dns-services-
implementations-11-3-0/2.html?sr=28642034
• Manual Chapter 10: BIG-IP Global Traffic Manager: Concepts> DNSSEC Keys and Zones
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-concepts-11-2-
0/gtm_dnssec.html?sr=28642034
• SOL9113: BIG-IP GTM support for Domain Name System Security Extensions
http://support.f5.com/kb/en-us/solutions/public/9000/100/sol9113.html?sr=29317825
• SOL7058: BIG-IP GTM ZoneRunner character support for DNS Resource Records
http://support.f5.com/kb/en-us/solutions/public/7000/000/sol7058.html?sr=29317841
• rndc communicates with the name server over a TCP connection, sending commands
authenticated with digital signatures. In the current versions of rndc and named, the only
supported authentication algorithm is HMAC-MD5, which uses a shared secret on each end
of the connection. This provides TSIG-style authentication for the command request and the
name server's response. All commands sent over the channel must be signed by a key_id
known to the server.
• rndc reads a configuration file to determine how to contact the name server and decide what
algorithm and key it should use.
• SOL 5739: Manually editing zone files while using ZoneRunner
http://support.f5.com/kb/en-us/solutions/public/5000/700/sol5739.html?sr=29319125
• Configuring GTM: Module DNS Overview
1.04 Explain the dataflow of the DNS query process [iterative, recursive, lame
delegation, host file, and resolvers].
Example: Explain recursive versus iterative
• Ref: 1, pp. 909-923.
• SOL 7055: Enabling DNS recursion on the BIG-IP GTM system
http://support.f5.com/kb/en-us/solutions/public/7000/000/sol7055.html?sr=29319273
• rfc 4697: Observed DNS Resolution Misbehavior
http://tools.ietf.org/html/rfc4697
• Configuring GTM: Module DNS Overview
1.06 Given a DNS hierarchical diagram determine what source IP the GTM will
receive the query from.
• Configuring GTM: Module DNS Overview
1.07 Identify DNS security concepts and their purpose [DDOS, DNSSEC,
AnyCast, DNSFirewall, site validation, iRules, and impacts of floating self-
IP versus non-floating self-IP listener]
• Manual Chapter: About System DoS and DDoS Attacks
http://support.f5.com/kb/en-us/products/big-ip_asm/manuals/product/bigip-dns-dos-firewall-
implementations-11-3-0/2.html?sr=28704965
• Manual Chapter: BIG-IP DNS Services: Implementations.
http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/bigip-dns-services-
implementations-11-3-0.html?sr=28705021
• DNSSEC - Security extension encompassing a suite of IETF specifications securing certain
kinds of information provided by DNS.
• AnyCast - Not unique to DNS, actually a networking concept implemented by using BGP.
Not really a security concept as much as a way to distribute service over multiple servers
over a geographic area. DDoS actually uses this concept.
• DNSFirewall - A firewall specific to monitoring DNS traffic/requests.
• Site validation - useful in ensuring valid information from known systems through the use of
digitally signed answers. Part of the specifications of DNSSEC.
• iRules - Open ended. iRules can be used to direct and handle traffic to preventing traffic
based on specific requirements.
• floating/non-floating self-IP listener
1.08 Describe data center, server/virtual server, and object monitoring including
explanation of resulting object statuses [prober pools, BigIP and generic
server objects, monitors, etc.].
Example: Identify the purpose and uses of prober pools
• Manual: BIG-IP Global Traffic Manager: Concepts
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-concepts-11-3-
0.html
• SOL 8170: Overview of BIG-IP GTM monitor timers
http://support.f5.com/kb/en-
us/search.res.html?q=sol8170&filter=p&requiredfields=lifecycle:release
• Configuring GTM: Module LDNS Probes and Metrics
• Configuring GTM: Module Monitors
1.09 Define the GTM load balancing methods and when to use them [dynamic,
static].
• Manual: BIG-IP Global Traffic Manager: Concepts
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-concepts-11-3-
0.html
• Configuring GTM: Module Load Balancing
1.11 Identify the purpose of GTM tools and when to use them [checkcert,
iqdump, etc.].
• Checkcert Utility
• SOL 7574: Monitoring SSL certificate expiration on the BIG-IP system
http://support.f5.com/kb/en-us/solutions/public/7000/500/sol7574.html?sr=28644702
• SOL 12420: The checkcert utility sends debug logs to the remote syslog server
http://support.f5.com/kb/en-us/solutions/public/12000/400/sol12420.html?sr=28644702
• iqdump
• SOL 8187: Troubleshooting BIG-IP device certificates
http://support.f5.com/kb/en-us/solutions/public/8000/100/sol8187.html?sr=28644786
• Manual: BIG-IP Global Traffic Manager: Concepts
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-concepts-11-3-
0.html
• SOL 14106 - Troubleshooting virtual server and link auto-discovery (11.x)
http://support.f5.com/kb/en-us/solutions/public/14000/100/sol14106.html?sr=29319381
• SOL 13312 - Overview of the BIG-IP GTM big3d_install, bigip_add, and gtm_add utilities
(11.x)
http://support.f5.com/kb/en-us/solutions/public/13000/300/sol13312.html?sr=29319389
• SOL 13690 - Troubleshooting BIG-IP GTM synchronization and iQuery connections (11.x)
http://support.f5.com/kb/en-us/solutions/public/13000/600/sol13690.html?sr=29319401
• Configuring GTM: Module Intelligent DNS Resolutions
1.12 Explain how zone transfers work [multi master, master/slave, DNSExpress,
incremental/full, updates (notify/expire)].
• Manual: BIG-IP Global Traffic Manager: Concepts
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-concepts-11-3-
0.html
• Ref: 1, pp. 896-898.
• Configuring GTM: Module Accelerated DNS Resolutions
1.13 Given a scenario determine the impact of a custom DNS profile for various
types of queries, determine what response will be given and where it will
come from.
Example: Explain all of the features that can be enabled in a DNS profile
(DNS cache, unhandled query, DNS Express, enable GTM, enable bind)
• Manual Chapter: Other Application-Layer Profiles: DNS Profiles
http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/ltm-concepts-11-3-
0/ltm_other_services_profiles.html?sr=28644390#1215229
• Configuring GTM: Module Accelerated DNS Resolutions
1.14 Given a scenario with a specific query source IP address and various pool
and Wide IP loading balancing methods and topology rules/regions
determine the response that will be given.
• Manual: BIG-IP Global Traffic Manager: Concepts
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-concepts-11-3-
0.html
• SOL 13412 - Overview of BIG-IP GTM Topology records (11.x)
http://support.f5.com/kb/en-us/solutions/public/13000/400/sol13412.html?sr=29319413
• Configuring GTM: Module Load Balancing
1.16 Explain the networking requirements of placing devices within a GTM data
center object
Example: Explain and identify GTM objects (Data center, link, server, virtual
server, prober pool, pool, wideIP)
• Manual Chapter: BIG-IP DNS Services: Implementations
http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/bigip-dns-services-
implementations-11-3-0.html
• Configuring GTM: Module Intelligent DNS Resolutions
Section 2, Deployment
2.01 Explain when to configure translation addresses for local data center
connectivity.
• Manual: BIG-IP Global Traffic Manager: Concepts
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-concepts-11-3-
0.html
• SOL 7820: Overview of SNAT features
http://support.f5.com/kb/en-us/solutions/public/7000/800/sol7820.html?sr=28646654
2.03 Given a set of requirements select the appropriate load balancing methods
[ex. wide IP level, pool level, different types and combinations].
Example: Given a scenario determine the load balancing decision based on
virtual server status and configure load balancing (single pool versus
multiple pools, effect of secondary and fallback mechanisms in the first
pool, effect of topology and topology records at the Wide IP level versus
pool level, iRule effects)
• Manual: BIG-IP Global Traffic Manager: Concepts
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-concepts-11-3-
0.html
2.04 Explain how to configure GTM to return non-wide IP supported records [ex.
MX, SRV, TXT records, etc.].
Example: Determine when to use ZoneRunner to manage DNS records on
GTM.
• Manual: BIG-IP Global Traffic Manager: Concepts: ZoneRunner
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-concepts-11-3-
0.html
• Configuring GTM: Modules Accelerated DNS Resolutions, Intelligent DNS Resolutions, and
Bind and ZoneRunner
• SOL 6963: Managing the BIG-IP BIND configuration file
http://support.f5.com/kb/en-us/solutions/public/6000/900/sol6963.html?sr=29356537
• SOL 5739: Manually editing zone files while using ZoneRunner
http://support.f5.com/kb/en-us/solutions/public/5000/700/sol5739.html?sr=29319125
• SOL 7176: F5 support for ZoneRunner, BIND, and the named process
http://support.f5.com/kb/en-us/solutions/public/7000/100/sol7176.html?sr=29356645
2.05 Given a scenario select the appropriate deployment type: screening mode,
DNS delegation, caching resolver, and DNS 6 to 4.
• Manual: BIG-IP Global Traffic Manager: Concepts
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-concepts-11-3-
0.html
• Manual: BIG-IP DNS Cache: Implementations
http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/bigip-dns-cache-
implementations-11-3-0.html?sr=29356757
• Manual: BIG-IP DNS Services: Implementations
http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/bigip-dns-services-
implementations-11-3-0.html?sr=29356761
• SOL 277: Delegating a subdomain to a BIG-IP GTM or Link Controller system from another
DNS server (9.x - 11.x)
http://support.f5.com/kb/en-us/solutions/public/0000/200/sol277.html?sr=29356705
• Configuring GTM: Module Accelerated DNS Resolutions, Intelligent DNS Resolutions, and
Advanced Topics
2.06 Given a scenario of specific virtual server status, pool and Wide IP load
balancing settings determine the answer returned [Single pool versus
multiple pools, effect of secondary and fall-back mechanisms in the first
pool, effect of topology and topology records at the Wide IP level versus
pool level, and iRule effects].
2.09 Explain the necessary steps and tools to add a new LTM to a sync group.
Example: Understand the minimal object requirements to get a sync group
up
Example: Explain how to add LTM to a sync group and on which host do
you run bigip_add.
• Manual: BIG-IP Global Traffic Manager: Implementations
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-implementations-
11-3-0.html?sr=28646530
• SOL13734 - BIG-IP GTM synchronization group requirements
http://support.f5.com/kb/en-us/solutions/public/13000/700/sol13734.html
• SOL 13312 - Overview of the BIG-IP GTM big3d_install, bigip_add, and gtm_add utilities
(11.x)
http://support.f5.com/kb/en-us/solutions/public/13000/300/sol13312.html?sr=29319389
• Configuring GTM: Module Intelligent DNS Resolutions and Advanced Topics
2.10 Explain the necessary steps and tools to add a new GTM to an existing
sync group.
Example: Describe how to add GTM to an existing deployment (add GTM to
the data center, which direction to run gtm_add, how to use gtm_add)
• Manual: BIG-IP Global Traffic Manager: Implementations
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-implementations-
11-3-0.html?sr=28646530
• SOL13734 - BIG-IP GTM synchronization group requirements
http://support.f5.com/kb/en-us/solutions/public/13000/700/sol13734.html
• SOL 13312 - Overview of the BIG-IP GTM big3d_install, bigip_add, and gtm_add utilities
(11.x)
http://support.f5.com/kb/en-us/solutions/public/13000/300/sol13312.html?sr=29319389
• sol14044: Removing and re-adding a BIG-IP GTM system to an existing GTM
synchronization group
http://support.f5.com/kb/en-us/solutions/public/14000/000/sol14044.html?sr=29356809
• Configuring GTM: Module Accelerated DNS Resolutions, Intelligent DNS Resolutions, and
Advanced Topics
2.15 Given a scenario, explain how to validate system health for proper
operation.
• Manual: BIG-IP iHealth User Guide
http://support.f5.com/kb/en-us/products/big-
ip_ltm/manuals/related/bigip_ihealth_user_guide.html?sr=28677802
• SOL 13397: Overview of HTTP health monitor request formatting for the BIG-IP GTM
system
http://support.f5.com/kb/en-us/solutions/public/13000/300/sol13397.html?sr=28677770
• Manual Chapter: Health and Performance Monitoring Statistics
http://support.f5.com/kb/en-us/products/em/manuals/product/em-health-activity-monitoring-
3-1-0/5.html?sr=28677770
• Configuring GTM: Module Monitors, Logs and Notification, and Advanced Topics
3.02 Given a scenario determine what is the effect of changing the features
enabled in a DNS profile.
Example: Including enabling/disabling recursion, protocol, unhandled
query behavior, and making sure BIND is not enabled in the profile or in the
GTM pools, etc.
• Manual Chapter: Other Application-Layer Profiles: DNS Profiles
http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/ltm-concepts-11-3-
0/ltm_other_services_profiles.html?sr=28644390#1215229
• SOL 7055: Enabling DNS recursion on the BIG-IP GTM system
http://support.f5.com/kb/en-us/solutions/public/7000/000/sol7055.html?sr=29319273
3.03 Explain how to renew device certificates and update them in the sync
group.
• SOL 6353: Updating an SSL device certificate on a BIG-IP GTM or BIG-IP Link Controller
system
http://support.f5.com/kb/en-us/solutions/public/6000/300/sol6353.html?sr=28675938
• SOL 13946: Troubleshooting ConfigSync and device clustering (11.x)
http://support.f5.com/kb/en-us/solutions/public/13000/900/sol13946.html?sr=28675938
• SOL 13690: Troubleshooting BIG-IP GTM synchronization and iQuery connections (11.x)
http://support.f5.com/kb/en-us/solutions/public/13000/600/sol13690.html?sr=28675938
• SOL 13734 - BIG-IP GTM synchronization group requirements
http://support.f5.com/kb/en-us/solutions/public/13000/700/sol13734.html
• SOL 13649 - Creating a device group using the Configuration utility
http://support.f5.com/kb/en-us/solutions/public/13000/600/sol13649.html
• SOL 13639 - Creating a device group using the Traffic Management Shell
http://support.f5.com/kb/en-us/solutions/public/13000/600/sol13639.html
• SOL 7754: Renewing self-signed device certificates
http://support.f5.com/kb/en-us/solutions/public/7000/700/sol7754.html?sr=29356821
3.05 Explain the importance of running compatible versions of big3d on the LTM
and GTM.
Example: Explain how to update big3d on LTM (big3d_install) and what
concerns might be when EM is also updating GTM
• SOL 13703: Overview of big3d version management
http://support.f5.com/kb/en-us/solutions/public/13000/700/sol13703.html?sr=28675754
• Supplemental Document: Updating the big3d Agent Manually
http://support.f5.com/kb/en-us/products/monitoring_pack/releasenotes/related/relnote-
f5mpk-updating-big3d-manually.html?sr=28675754
• SOL 9742: Enterprise Manager may need to install a new big3d data collection agent on
managed devices
http://support.f5.com/kb/en-us/solutions/public/9000/700/sol9742.html?sr=28675754
• Manual Chapter: big3d Agent
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-concepts-11-2-
0/gtm_big3d.html?sr=28675754
• Example: Explain how to update big3d on LTM (big3d_install) and what concerns might be
when EM is also updating GTM
• SOL14304: BIG-IP GTM sync group members running big3d 11.3.0 may experience iQuery
communication issues with systems running previous versions of big3d
http://support.f5.com/kb/en-us/solutions/public/14000/300/sol14304.html?sr=29356941
• BIG-IP Global Traffic Manager: Concepts: Communications Between BIG-IP GTM and Other
Systems
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-concepts-11-3-
0/2.html?sr=29356957
3.07 Explain the effect of adding a resource record without using ZoneRunner.
Example: Explain how to maintain zones via ZoneRunner, including moves,
adds, and deletions
• Manual: BIG-IP Global Traffic Manager: Concepts
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-concepts-11-3-
0.html
• SOL 5739: Manually editing zone files while using ZoneRunner
http://support.f5.com/kb/en-us/solutions/public/5000/700/sol5739.html?sr=28676082
• SOL 7176: F5 support for ZoneRunner, BIND, and the named process
http://support.f5.com/kb/en-us/solutions/public/7000/100/sol7176.html?sr=29356645
• Configuring GTM: Module Appendix C: BIND and ZoneRunner
3.09 Identify GTM specific command line tools and TMSH GTM specific
commands.
Example: Show a GTM iQuery.
• Manual: Traffic Management Shell (tmsh) Reference Guide version 11.3.0 (MAN-0306-04)
http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/bigip-tmsh-11-3-
0.html?sr=28675254
• SOL 13690: Troubleshooting BIG-IP GTM synchronization and iQuery connections (11.x)
http://support.f5.com/kb/en-us/solutions/public/13000/600/sol13690.html?sr=28675234
• SOL 14106 - Troubleshooting virtual server and link auto-discovery (11.x)
http://support.f5.com/kb/en-us/solutions/public/14000/100/sol14106.html?sr=29319381
• Configuring GTM: Module Intelligent DNS Resolutions