304 · F5-CTS, BIG-IP APM

BIG-IP APM Specialist

For engineers preparing for the 304 exam. Configure, implement, troubleshoot and maintain APM, and explain how it interacts with the authentication and authorisation systems your organisation already runs.

AAA methods, SSO and SAML, network and portal access, the Visual Policy Editor, iApps, session management, EPSEC and Secure Web Gateway. Six blueprint sections and thirty objectives, the broadest of the specialist exams.

Waitlist members get first access and launch pricing.
Full course €499. Covers all six sections of the 304 blueprint.

Join Wait List
 

Status · In build

Waitlist members get first access and launch pricing. Pricing €499 > Full Course

Created by Graham Mattingley. Fourteen years F5-certified. Banking, aviation, government, and F5 instructor.

Course overview

304 identifies engineers who can configure, implement, troubleshoot and maintain APM across a range of environments, and who can explain how it interacts with industry standard remote access, authentication and authorisation systems.

It is the broadest of the specialist exams: six sections and thirty objectives spanning AAA and SSO, SAML federation, network and portal access, the Visual Policy Editor, iApps, session management and security. APM sits between your users and the identity systems your organisation already runs, so this course covers both sides of that boundary.

Aligns directly with the official 304 blueprint, covering all thirty objectives across six sections.

What's included

βœ“Instructor-led, self-paced video training aligned directly to the 304 blueprint
βœ“AAA configuration across Active Directory, LDAP, Radius, RSA SecurID, TACACS and Kerberos
βœ“SAML as both Service Provider and Identity Provider, including Single Logout
βœ“Visual Policy Editor built up properly: branches, macros, session variables, ending types
βœ“Network access, portal access, App Tunnels and Web Access Management compared
βœ“Diagnostics with session reports, sessiondump, ssldump, tcpdump and APM debug logging
βœ“Private course community access for discussion and 304 exam support

Join the 304 Wait List

Receive monthlyΒ build updates, preview content, and early access notifications.

What Will You Be Able To Do?

APM fails in ways that look like someone else's problem. A Kerberos SPN, an LDAP query, a policy branch that never evaluates. 304 tests whether you can find it.

After completing this course, you'll be able to:

βœ… Configure any of the AAA methods - Active Directory, LDAP, Radius, RSA SecurID, TACACS, Kerberos, NTLM and client certificate authentication

βœ… Prove the auth service is reachable - and read adtest and ldapsearch output when it is not

βœ… Choose the right SSO type - and get the Kerberos SPN requirements right first time

βœ… Deploy SAML as SP or IdP - integrate with PING, Okta or another vendor, including Single Logout

βœ… Build a VPE policy that behaves - branches, macros, session variables, and ending types that do what you meant

βœ… Pick the right access method - network access, portal access, App Tunnels or Web Access Management, on the requirement

βœ… Diagnose a failed session - session reports, session variables, sessiondump, ssldump, and APM debug logging

βœ… Secure the deployment - ACLs, timeouts, MFA, GeoIP and IP intelligence, EPSEC client checks and SWG

You will leave this course able to build an access policy, explain it to an identity team, and find out why it broke.

304 Course Curriculum

Private Community Included with the Course

Share a private community with other members of this course. Course community membership is permanent.

βœ… Ask questions and get practical advice from other course members on the same learning journey.

βœ… Share real-world scenarios, problems, and solutions.

Want Personalised Support?

Add a 1:1 Strategy Session. Get a private hour with Graham to:

βœ… Review your TMOS Administration study/knowledge gaps
βœ… Review specific areas of the blueprint that are blockers
βœ… Live question sessions to test exam readiness

Additional Cost: €100

Full Video Course

Presentations, F5 GUI and CLI demonstrations, AAA and SSO configuration, SAML federation walkthroughs, Visual Policy Editor built up branch by branch, and live session troubleshooting, all aligned to the 304 blueprint.

Watch Every Configuration (GUI & TMSH)

Guided demonstrations covering AAA objects, SSO credential mapping, SAML SP and IdP configuration, network and portal access profiles, VPE macros and branches, EPSEC checks, and reading a failed session back to its cause.

Lesson Knowledge Checks

Targeted assessments after each module to reinforce key concepts and ensure you are progressing toward 304 exam readiness. With six sections and thirty objectives, the checks matter more here than on any other specialist exam.

304 Course FAQs

Your instructor

I don't teach exam shortcuts. I teach how TMOS actually behaves under production traffic, and how to make confident decisions when it's 2 AM and something's on fire.

Graham Mattingley

Graham Mattingley

CCIE since 2001 | F5 401 Certified Solution Expert | OWASP member

Thirty years in application development, twenty in application delivery, F5-certified for fourteen. I've deployed and secured F5 solutions for banking, aviation, and government systems across Europe, and taught this material face to face to the engineers who run it.

This is the operational knowledge I wish I'd had twenty years ago, distilled from production deployments you won't find in official training materials.

How this course is delivered

  • Instructor-led, structured video lessons aligned directly to the thirty 304 blueprint objectives

  • Step-by-step configuration walkthroughs using the F5 GUI and TMSH

  • Each AAA method configured and then deliberately broken, so you recognise the failure

  • Visual Policy Editor built up from a single logon object to a branched policy with macros

  • Live diagnostics using session reports, sessiondump, ssldump and APM debug logging

  • Self-paced access, allowing you to study around professional commitments

  • Structured modules that keep the six blueprint sections separate rather than blurring them together

Prerequisites & Requirements

F5 Certified Administrator, BIG-IP (F5-CA) is required before sitting 304. Since May 2025 that is earned by passing F5CAB1 to F5CAB5.

Identity and access awareness helps as much as BIG-IP knowledge. Recommended:

  • Familiarity with Active Directory or LDAP directory structure

  • Understanding of how authentication and authorisation differ in practice

  • Awareness of SSO and federation concepts, which the course covers from the ground up

  • Working knowledge of BIG-IP virtual servers, profiles and SSL

Access to a BIG-IP lab environment is recommended for hands-on practice. However, the course includes lifetime access to all demonstrations, allowing you to revisit configuration walkthroughs as needed.

Lab Access Info

What happensΒ next?

  • Join the waiting list to be notified when enrolment opens

  • Receive monthly, blueprint-aligned TMOS administration scenarios and diagnostic insights while the course is in development

  • Get early access and priority enrolment before the public launch

Join the Wait List