Showing posts with label training. Show all posts
Showing posts with label training. Show all posts

Tuesday, September 5, 2017

DevCentral’s Featured Member for September – Rob Carr

Rob Carr is a Senior Trainer/Professional Services Consultant with Red Education Pty in Australia, covering the Oceania and Asia markets. He has done training and engagements from New Zealand to Taiwan and points in between. About 60% of his time is running F5 courses, ranging from the from the introductory Admin course through the high-level courses like AFM, ASM or iRules. He enjoys the mix of work, where teaching allows him to be social and PS work lets him delve into the technical nitty-gritty. Rob is also DevCentral's Featured Member for September!

DevCentral: You were an F5er (ProServ Consultant) from 2013-15 and continue to be a very active contributor in the DevCentral community since then. What keeps you involved?
Rob: Long before I did PS Consulting for F5, I worked for F5 in Seattle, first as a Network Support Engineer and then as Software Test Engineer, and I always found DC to be extremely useful. While F5 puts considerable energy into its product documentation and knowledge base articles, there are times when you need an ‘outside’ perspective to really understand what a feature is and how to use it. I always exhort my students to use DC as a resource, and not just for iRules. 

I stay active because I use the site to answer my own questions and because I appreciate it when someone knowledgeable contributes a write-up or a really solid comment. I try and give back by commenting when the subject of a question is one in which I have experience.
DC: Tell us a little about the areas of BIG-IP expertise you have.
RC: I’ve been working with BIG-IP since 2005, when there were only two products, BIG-IP and 3DNS (FirePass joined F5 a few months after I did), and those two (well, the current iterations of LTM and DNS) are my strongest products. I’ve also worked with BIG-IP ASM, APM and AFM over my career. Today, I’m most comfortable with BIG-IP ASM and general Application Delivery more generally at this point.
DC: You are a Consultant & Trainer at Red Education. Can you describe your typical workday?
RC: If I’m training then I try to be onsite about an hour before the students. I need the time to setup the room, settle my thoughts and flip through the material we need to cover that day. Generally, training is a nine-to-five experience, although that can be modified by where the training is being done – in some countries, courses start later, then run into the early evening. Regardless of the specific hours, my tasks for the day are pretty much the same: cover the material, answer student questions and redirect where needed, proctor the labs and troubleshoot course and student issues. It’s almost like being on stage for an eight-hour show. 
Consulting, on the other hand, is generally quite a bit more solitary. I do most of my work remotely, so once I’ve met with the client and we’ve had our kickoff activities, I’m back in Melbourne working from my home office. It’s not unusual to have a conference call once a day with the customer and technical staff and there is always email communication about the design and documentation tasks. 

In the background, there is always communication with the constellation of trainers and consultants that I work with, sharing ideas, running questions past one another or bantering.
DC: You have a number of F5 Certifications including most of the Technology Specialist (LTM, GTM, APM, ASM) certifications. Why are these important to you and how have they helped with your career?
RC: I have all the F5 Certifications at this point, including the 401 Security Solution Expert exam and I suppose I’m a bit proud of that fact. I think F5’s certification exams are pretty good at covering what you need to know to be successful working on F5 systems in the enterprise, certainly more so than some of the other vendor exams.
In Australia, engagements often come with a requirement that you have certification for the product or products, so in that sense having the certifications has been good for my career. More generally, having the certifications has given me more confidence in representing my skills to prospective clients.
DC: Describe one of your biggest BIG-IP challenges and how DevCentral helped in that situation.
RC: Recently, I was on an engagement where the customer was migrating internal architectures for some highly fragmented legacy applications, as part of a PCI compliance project. We needed to replace many mod_proxy implementations and to mitigate application issues that came up during this transition, all on a short timeline. We ended up using multiple iRules with each service, providing routing and forwarding and fixing issues like improperly set cookie attributes. iRules is such a powerful and flexible solution that in the near term, given our timeline, it was the best and fastest way to manage the application issues.
DC: Lastly, if you weren’t an IT admin – what would be your dream job? Or better, when you were a kid – what did you want to be when you grew up?
RC: I’ve always enjoyed gardening and I’m fond of zoos and animal parks, so if I wasn’t working in IT, I think I would like to be a gardener at the zoo.

Thanks Rob! Check out all of Rob's DevCentral contributions, connect with him on LinkedIn and visit Red Education.

Tuesday, August 15, 2017

I’ve Successfully Failed the F5 Certification 201-TMOS Administration Exam

Yup, you read that right. I did not pass the F5 Certified BIG-IP Administrator test I took while at F5 Agility 2017. And I’m not ashamed since it was a challenging test and I will be trying again.

Sure, I went through Eric Mitchell’s (F5er) comprehensive 201 Certification Study Guide along with the TMOS Administration Exam Blueprint. However, I probably should have taken more time ON a BIG-IP messing around…especially for tmsh commands…which is where, I believe, I got tripped up. This is key. Reading and memorizing commands along with some practicing can only get you so far. Doing it regularly is what’s needed. This is a key feature of the exams, particularly as you move up the exam expertise. The exams are designed to test real knowledge and experience, not if you can cram the night before. Pretty sure my errors came with tmsh and the UCS upgrade questions since I had limited experience in those areas.

Going in, I was a bit less confident (than from the 101) but also, less anxious. And about three-quarters through the exam I was feeling pretty good. I might pass this thing. However, the 201 Certification exam is not something to take lightly and is much more challenging than the 101. While the 101 has a 70% pass rate overall, the 201 hovers around 67% pass rate overall. 69% correct is a pass – I got 63%. I probably would have received my diploma from an educational institution but for Dr. Ken, a 63 is not a ‘pass’ with the F5 Certification Program. But that’s OK and why I like the program. At whatever level, a pass is a true achievement. You know your stuff.

At Agility 2017, the F5 Professional Certification team administered 227 exams. They had 245 scheduled so only 18 no-shows for whatever reason. When I took the exam on Monday, there was a constant flow of folks taking the exams and over the course of the event, I spoke to many who were either about to take one or had already completed theirs. No matter pass or fail, all were impressed with the caliber of the exams.

For the week, the disposition is as follows:

So you don’t have to work out the percentages:

Slight edge to the Pass group, congratulations…but still, you got a 50:50 shot.

Even though I failed, I’m glad to have taken it and know what I need to brush up on for my next attempt. For others that also failed, don’t be discouraged. While in Chicago, I was reminded of this Michael Jordan quote:
I've missed more than 9000 shots in my career. I've lost almost 300 games. 26 times, I've been trusted to take the game winning shot and missed. I've failed over and over and over again in my life. And that is why I succeed.
ps

Tuesday, July 12, 2016

The Road to F5 Certification

Over the last 4 months, the DevCentral team has been preparing for the F5 Certification exam. We’ve met a number of times for group study and for each session, we reviewed a particular section of the Exam 101 - Application Delivery Fundamentals Study Guide. We prepared and presented a certain topic and had open discussions about particular use cases, customer scenarios and even played some guessing games as to what might be asked on the exam for that section.

Now the time has come to take the test.

Since the DevCentral team will be at Agility 2016 in Chicago this year, we decided to take advantage of the Certification Team’s mobile testing center. While you can certainly go to one of Pearson Vue’s test centers, the Certification Team will be on hand at F5 Agility to administer their various exams for those looking to get F5 Certified. It’s a pretty cool set up – almost like a band on a mini regional tour. They’ll have everything you need to take the test.

I gotta tell you, I’m a little nervous.

I’m sure I’ll be able to nail sections 2-5 since those are the areas I’ve focused on for the past decade…it’s the first part, OSI, that I’m a little weary. Not that I don’t know my 7 layers – All People Seem To Need Data Processing – but maybe some of nuances or lack of recent real world subnetting that concerns me. I’ll use this last month before the exam to keep prepping to make sure I don’t embarrass myself.

But let's look at the stats.

Recently Ken Salchow, F5’s Sr. Manager Professional Certifications, has posted some interesting statistics about the program, particularly pass rates and certification by region. Ken notes about the pass rate graph, ‘I am also often asked about exam pass rates ... which is not an easy thing to really post. Below is a graph that shows ALL TIME pass rates by exam. It is important to note that these pass rates encompass thousands of exams and even different versions of exams. As such, take these with a grain of salt and realize that if I did a 12-month average, 24-month average and last month average, they would all differ from the below. Oh ... and have I mentioned how much I distrust data coming from our candidate management system?? Yeah ... so ... you've been warned.

And the graph:


So there's a 70% pass rate on the 101. Fairly decent.

Ken also posted another chart which shows the breakdown of certification by region as a percentage of the whole.


Nice mix of global certifications.

We - the DevCentral team - will take some pictures and let you know how we did. If you are at Agility and taking a Certification exam this year, let's compare notes for the final wrap. Pass or Fail.

My energy says, 'Success!'

ps

Related:

Wednesday, April 13, 2016

Let the Training Begin!

A few weeks ago I mentioned that I was on a journey to getting properly trained and reacquainted with the more technical nuances of F5 solutions with the goal of achieving F5 Professional Certification sometime this year. In fact, most of F5’s DevCentral team is also shooting for certification and we’ve set up our study path.

As a refresher, F5 has a number of educational programs to help you get acquainted, get fully trained or become a Certified Professional with F5 gear. From free online courses to instructor led classroom seminars to challenging your knowledge with a certification, F5 can help you, as it is helping me, understand the inner workings of BIG-IP. I began at F5 University with the Getting Started series and was able to get through a number of modules at my own pace.

This week, the DC team is in Seattle at the Mother Ship and we decided to kick off our study prep while we’re together. This is for the initial 101-Application Delivery Fundamentals exam and we’re using Eric Mitchell’s excellent Study Guide as our guide. There is also an Exam Blueprint available that goes through the objectives of each section and gives examples of the types of questions asked. Um, what's the purpose and functionality of MTU and MSS again?

The 101-Application Delivery Fundamentals test is the first exam required to achieve F5 Certified BIG-IP Administrator status. All candidates must take this exam to move forward in the program. Successful completion of the 101 exam acknowledges the skills and understanding necessary for day-to-day management of Application Delivery Networks (ADNs). The 101 exam is not so much, how do you do this on a BIG-IP but more about the basics of the OSI model, networking, protocols, common traffic management/load balancing concepts, cryptographic services and application delivery platforms in general. The essential knowledge needed to deploy any application delivery controller.

We’ve decided to each take and prepare a section of the study guide and present to the team. We’ve set up weekly meetings and each week is an exam section. This week is the OSI model and (theoretically) in 5 weeks, we should be ready to take the exam. If you are prepping or planning to get certified at our Agility event in Chicago this summer, you and your team may want to consider that approach. All the learning benefits, with slightly less stress.

So that’s our most recent update as we continue on the certification path. If you’d like a step-by-step guide, including how to register and schedule your exam, check out Austin Geraci’s article Becoming F5 Certified - BIG-IP Administrator Certification - 101 & 201 Exams and/or join the F5 Certified! Professionals group on LinkedIn. Good stuff.


ps


Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, March 15, 2016

Jumping on the Rails of the Technical Train

I used to be technical, highly technical. You know the kind…more comfortable with CLI rather than GUI, limited use of CAPS at the beginning of sentences and proficient at configuring & troubleshooting a slew of devices from multiple vendors. But after a couple role changes over the years, my technical acumen has slightly diminished. Again, you probably know the drill that if you’re not tapping away at it daily, some of those skills dwindle. Plus, with new technology replacing the stuff you knew 10 years ago, it often feels like starting over.

But don’t fret! As with anything, you can regain some prowess and learn new tricks with a bit of training. Get on that bike and ride!

That’s what I’m going through now.

When I joined the DevCentral team, I quickly realized that our community is much smarter than I when it comes to the intricacies of our solutions. My initial reaction to many of the questions that get posted on DevCentral sound like the ‘Aaaaaahhhhhh, Ahhhhhh,’ from Bevis and Butthead. I have no idea. I’ll Alt-Tab to the AskF5 Knowledge Base to check if there is already an answer and often there is. But when it is a unique situation or something with iRules, I look blankly at the screen and wonder, ‘How can I help, when I don’t even know.’

One of the great things about working at F5 is that they allow us to take whatever training is needed to be proficient at our job. Over the last couple weeks I’ve been doing just that – initially digging in to F5’s free Web Based Training.

F5 has a number of educational programs to help you get acquainted, get fully trained or become a Certified Professional on F5 Solutions. From free online courses to instructor led classroom seminars to challenging your knowledge with a certification, F5 can help you, as it is helping me, understand the inner workings of BIG-IP. I began at F5 University with the Getting Started series and was able to get through a number of modules at my own pace. We have programs for both partners and customers and is a great way to learn the fundamentals of the BIG-IP system.

Next for me, will probably be some classroom training with hands on configuration and the entire DevCentral team will embark on a path to F5 Certification. Hear that Ken? We’re coming for ya!! We’re going to start a mini-study group using many of the resources available and chronicle our progress. The idea is that we’re like you – we know a lot already but want to get deeper in our understanding and for me, better at providing the details of our technical solutions.

Join us over the next bunch of months as we share our experiences of becoming an F5 Certified Professional.


ps

Wednesday, May 8, 2013

Interop2013: F5 Certification Program

I catch up with F5 Certification Manager Ken Salchow to talk about how the Certification Program has grown over the last year since the announcement at Interop 2012. Ken discusses the new exams, his certification philosophy and how this all fits within the tech industry. F5's New Technical Certification Program Helps Define and Measure the Skills Required for Today's IT Complexities.

 

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, April 29, 2010

CSRF Prevention with F5's BIG-IP ASM v10.2

Watch how BIG-IP ASM v10.2 can prevent Cross-site request forgery.  Shlomi Narkolayev demonstrates.  See how a CSRF is first accomplished then blocked by ASM. The configuration of CSRF protection is literally a checkbox.

ps

Technorati Tags: F5, infrastructure 2.0, integration, collaboration, standards, cloud connect, Pete Silva, F5, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, blog

Digg This

Wednesday, March 17, 2010

Self Serve Security

Education of users has become a hot topic of late.  The final keynote at the recent RSA Conference was all about using education to combat cybercrimeThis article has statistics showing that, when Small and Mid-Market companies were asked, ‘what would help improve the level of security at their companies,’ 75% (48% for employees & another 25% for senior management) said Security Awareness.  And, the recent issue of SC Magazine featured an article where Dan Beard, the Chief Administration Office for the House of Representatives says that organizations must educate end users and that end user education is the weakest link in cyber security.  In that same article, Stephen Scharf, CISO at Experian explains:

“The human element is the largest security risk in any organization,”…“Most security incidents are the result of human errors and human ignorance and not malicious intent. Therefore, it is critical that significant effort is focused on education and awareness to reduce these occurrences.”

02840 The human element has always played a role in security, cyber or otherwise.  Growing up in Rhode Island, we used to always leave the keys in the ignition of the vehicles parked in our driveway.  We felt safe were we lived – and granted, we lived in a rural area so the main crimes committed were things like stealing eggs from Carpenter’s Farm.  Certainly, there are still plenty of areas and towns that have that type cocoon.  As I went off to college in Milwaukee, I had to remind myself early on – ‘you’re not in Wakefield anymore,’ since I’d instinctively leave my wallet crammed in the sun visor of my Rabbit Diesel.  I had to change my behavior when I moved from a small rural area to a larger city.  Internet users must do the same but we are creatures of habit.  Similar to leaving a wallet in the car, since that’s what I did most of driving life up to that point, many internet users still behave as if it’s 1995 and they are still on Prodigy.  The threats are different and more severe but behavior is the same.  Times change but sometimes people don’t, won’t or can’t.  

As all those articles point out, End User Education is vitally important to any organization and should be a key part of the overall IT security strategy.  Users knowing what and what not to do when something seems fishy is an important part of your defense – especially when it’s something your firewalls, WAFs, IDS/IPS and other perimeter mechanisms might have missed.  Education needs to be ongoing however and not a one shot deal since, according to Dr. Maxwell Maltz, it takes 21 days to make or break a habit.  This has since been deemed a myth and everyone is different but it does bring up a good point.  Security education, training and knowledge is not an overnight cram session – any security professional will attest to that.  A single afternoon meeting going over ‘corporate policies for end users’ regarding information security will not help those who already have bad habits.  It needs to be ongoing, consistent and relevant to their daily lives, including the serious consequences of poor behavior.  Help users understand the risks/threats, break the bad habits that might lead to exposure and secure your infrastructure in a way that no piece of hardware/software can.  Help users help themselves.

While not directly security related, F5 recently started offering Free Web Based Training for our end users.  IT admins are end users too, ya know.  F5 Networks Web-Based Training (WBT) courses introduce you to basic technology concepts related to F5 technology, recent changes to F5 products and basic configurations for BIG-IP Local Traffic Manager (LTM).   These are self-paced and you can access them at any time and as many times as you like.  The cool thing is if you complete all of the lectures and labs for the LTM Essentials WBT, you have met the prerequisite requirements for the Advanced Topics, Troubleshooting, and iRules classes.

ps

Related Items:

Technorati Tags: Pete Silva,F5,security,application security,network security, business, education, technology

Digg This

Thursday, March 11, 2010

In 5 Minutes Video - How I Create an ‘In 5 Minutes or Less’ Video

Thought it would be fun to produce one of these even though I got a new timer now.  I show how I create an In 5 Minutes Video, In 5 Minutes or Less. Behind the scenes in 5 Minutes.   :-)

ps

Technorati Tags: Pete Silva,F5,security,application security,network security, education, technology, social networking, webinar, video

Digg This

Friday, February 26, 2010

A is for Application, J is for Jacked

…Criminal-toasty Application Jacked, Data’s tasty stolen too, You’re Application’s Hacked.  Application’s Jacked, Application’s Jacked - hum hum the rest in your head, glad to plant a jingle in you, to sing out all day!

Almost every day now, there seems to be a report about some ‘important’ system getting breached or some credit cards/identities being stolen or insecure infrastructures getting exposed with schools, universities, municipalities, states and even entire countries being the latest victims.  The recent 7Safe UK Security Breach Investigations Report stated, “86% of all attacks, a weakness in a web interface was exploited” and in his blog last week, Jeremiah Grossman wrote about the discrepancy in security spending verses the types of attacks that occur.  He breaks down the numbers to show that most of the security spending goes to perimeter defense like firewalls and says, ‘Organizations spend their IT security dollars protecting themselves from yesterday’s attacks, at the network/infrastructure layer, while overlooking today’s real threats.’ 

This got me thinking – will we ever get ahead of the game?  Is it a question of habit?  Is it being uninformed or not understanding the true nature of the threats?  Is it just checking the compliance box and not really going after true protection?  Is it a budget, education, staffing or perception issue?  Are the crooks way smarter?  Are there too many areas to secure – applications, code, infrastructure, DNS, data, and any other piece that needs to be protected?  Are there just a whole mess of insecure systems on the internet just waiting to get jacked?  Or a combination of all these?  Probably depends on many, mixed factors depending on organization, personnel, region and what can be accomplished within whatever boundaries are placed on those who are tasked to implement a solution.  Many security professionals over the years focused on a particular discipline like network, database, application and so forth yet many of those same folks are now tasked with understanding and securing all areas of the organization.

IMG00003 Almost every second of our life, we make choices/decisions hopefully based on the best information we have at the time.  Maybe we ask for additional advice, if available, to make a more informed decision.  Sometimes emotions come into play when trying to come to a rational conclusion and we all know the head and the heart can pull you in opposite directions.  There’s a part of me that wants to scold those who are lazy with securing data.  (Incidentally, I did that last night at the Disney on Ice show – one of the vendors had a clipboard with a stack of credit card receipts sitting right in front of the register for people to use to sign their slips – I could have easily slipped that into my jacket while he wasn’t looking and disappeared into the crowd with a stack of signed CC receipts.  I informed him that his ‘ease of use’ was actually not so smart.  He pulled it and later, while the clipboard was still there, the receipts were absent.)  Then there’s the other side that feels the need to educate and help those who might not understand the ramifications of their actions – the softer side of psilva.

In our personal life, while we might ponder or struggle with the huge, life changing decisions like a job change or moving the family, and after careful consideration we usually make the right choice but it’s all the little miniscule, insignificant decisions we make throughout the day that defines our character.  When the basis for our decisions is coming from several different factors and the outcome can effect many swaths both across the organization and the public at large, that can make it a much more difficult endeavor, especially when it comes down to Infrastructure vs. Application, even though both should get attention.  We can yell, bang our head against the wall, plead and beg, but security is a though beast to tame for typical IT departments.  Even if they do declare Application Security is top priority, there may be many other factors holding them back.  We probably still have a way to go when it comes to prioritizing dollars based on actual attack stats until it hits close to home – by then, it’s too late.

ps

Technorati Tags: Pete Silva,F5,security,application security,network security, business, banks, banking, education, economy, technology

Digg This

Friday, February 19, 2010

F5 Web Media On-Demand

We’ve had some exciting announcements of late, like the BIG-IP Edge Gateway and the BIG-IP LTM VE, and lots of great content has been developed to highlight the benefits of these solutions.   It’s been a while since I’ve updated you about our Social Media sites and the various ways we deliver F5 content.   More than a year ago, we started to follow and contribute text, audio and video to the multitude of public Social Media outlets.  DevCentral has always been our social, community driven site, well before some of these newer social networks but we also recognized the need to engage with the various communities on the internet.  What started out as experiment, especially the Audio Whitepapers, multi-media has now become a mainstay of the various forms of F5 content offered, allowing you to get the latest from F5, anytime and anywhere.

Recent Videos

 

Recent Audio White Papers

 

F5 Networks Social Media & Content Sites

 

Thanks for reading, listening and watching.  If there is anything you’d like to see, let us know!!

ps

Technorati Tags: F5, BIG-IP, v10.1, Edge Gateway, Pete Silva, security, application security, network security, blogging, blogs, social networking

Digg This