303 · F5-CTS, BIG-IP ASM
BIG-IP ASM Specialist
For engineers preparing for the 303 exam. Design, implement and maintain ASM policies, including the advanced features, and understand the applications you are protecting.
I have thirty years in application development and ten as an OWASP member. That means you get the attacker's view and the developer's view alongside the policy configuration, so a violation stops being a log line and starts making sense.
Waitlist members get first access and launch pricing.
Full course β¬499. Covers all four sections of the 303 blueprint.
Status · In build
Waitlist members get first access and launch pricing. Pricing €499 > Full Course
Created by Graham Mattingley. Fourteen years F5-certified. Banking, aviation, government, and F5 instructor.
Course overview
303 identifies engineers who can design, implement and maintain ASM including its advanced features. The blueprint expects you to convert an application security requirement into a working policy, tune it without breaking the application, and explain what a violation actually means.
Most ASM training teaches the interface. This course teaches the applications as well. Thirty years writing them and ten years in OWASP means you get the developer's view of why a parameter is exploitable and the attacker's view of what they do with it, alongside the policy configuration.
You will finish with more than the exam requires. That is deliberate, and it is why the material stays usable after you pass.
Aligns directly with the official 303 blueprint, covering all twenty-four objectives across four sections.
What's included
Join the 303 Wait List
Receive monthlyΒ build updates, preview content, and early access notifications.
What Will You Be Able To Do?
ASM is easy to switch on and hard to run. 303 tests whether you can build a policy that stops attacks, survives contact with a real application, and can be explained to the people who own that application.
After completing this course, you'll be able to:
β Explain the OWASP Top Ten properly - what the attack does, why the application allows it, and what ASM does about it
β Choose a deployment method from requirements - vulnerability scanner, web services, template or rapid deployment, and say why
β Run the automatic policy builder deliberately - understand staging, enforcement readiness, and when to trust what it has learnt
β Structure a policy properly - URLs, parameters, file types, headers, sessions and logins, content profiles, CSRF, DataGuard, bot defence
β Tune out false positives without opening a hole - the trade-off between security, manageability and performance made explicit
β Read a violation and know what happened - and whether attack traffic was permitted through
β Integrate vulnerability scan output - and manage policies with import, export, merge and revert
β Diagnose ASM performance problems - iRule impact, traffic spikes, Guaranteed Logging, and policy history against system graphs
You will leave this course able to run ASM in production, not just pass an exam about it.
303 Course Curriculum
Section 1 β Architecture, Design and Policy Creation
Section 2 β Policy Maintenance and Optimisation
Section 3 β Review Event Logs and Mitigate Attacks
Section 4 β Troubleshoot
Private Community Included with the Course
Share a private community with other members of this course. Course community membership is permanent.
β Ask questions and get practical advice from other course members on the same learning journey.
β Share real-world scenarios, problems, and solutions.
Want Personalised Support?
Add a 1:1 Strategy Session. Get a private hour with Graham to:
β
Review your TMOS Administration study/knowledge gaps
β
Review specific areas of the blueprint that are blockers
β
Live question sessions to test exam readiness
Additional Cost: β¬100
Full Video Course
Presentations, F5 GUI and CLI demonstrations, policy building walkthroughs, attack signature lifecycle, violation analysis and tuning sessions, plus the application-side explanation of each OWASP category, all aligned to the 303 blueprint.
Watch Every Configuration (GUI & TMSH)
Guided demonstrations covering the deployment wizard, automatic policy builder, signature sets and staging, DataGuard, CSRF protection, bot defence, logging profiles, and tuning a policy against live traffic without breaking the application.
Lesson Knowledge Checks
Targeted assessments after each module to reinforce key concepts and ensure you are progressing toward 303 exam readiness. Questions cover both the ASM configuration and the application behaviour underneath it, because the exam assumes you understand both.
303 Course FAQs
Does passing 303 give me a certification?
Do I need F5-CA before taking 303?
Does this course include practical configuration demonstrations?
Do I need to understand web application development?
What should I take after 303?
Your instructor
I don't teach exam shortcuts. I teach how TMOS actually behaves under production traffic, and how to make confident decisions when it's 2 AM and something's on fire.
Graham Mattingley
CCIE since 2001 | F5 401 Certified Solution Expert | OWASP member
Thirty years in application development, twenty in application delivery, F5-certified for fourteen. I've deployed and secured F5 solutions for banking, aviation, and government systems across Europe, and taught this material face to face to the engineers who run it.
This is the operational knowledge I wish I'd had twenty years ago, distilled from production deployments you won't find in official training materials.
How this course is delivered
-
Instructor-led, structured video lessons aligned directly to the twenty-four 303 blueprint objectives
-
Each OWASP category explained from the application side before the ASM mitigation is shown
-
Step-by-step policy building walkthroughs using the F5 GUI and TMSH
-
Live tuning sessions working through false positives on real application traffic
-
Violation analysis: reading the log, deciding what it means, and choosing the mitigation
-
Self-paced access, allowing you to study around professional commitments
-
More depth than the exam strictly requires, so the material remains useful in production
Prerequisites & Requirements
F5 Certified Administrator, BIG-IP (F5-CA) is required before sitting 303. Since May 2025 that is earned by passing F5CAB1 to F5CAB5.
Application awareness matters here as much as BIG-IP knowledge. Recommended:
-
Understanding of HTTP requests, responses, headers and parameters
-
Familiarity with how web applications handle sessions and logins
-
Awareness of common web attack categories, which the course covers from the ground up
-
Working knowledge of BIG-IP virtual servers, profiles and logging
Access to a BIG-IP lab environment is recommended for hands-on practice. However, the course includes lifetime access to all demonstrations, allowing you to revisit configuration walkthroughs as needed.
Lab Access InfoLab Licence Assistance
We can assist you with obtaining the F5 Lab Licence as well as installation and setup on your computer/laptop
What happensΒ next?
-
Join the waiting list to be notified when enrolment opens
-
Receive monthly, blueprint-aligned TMOS administration scenarios and diagnostic insights while the course is in development
-
Get early access and priority enrolment before the public launch