Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free F5 Networks BIG-IP Administration Data Plane Concepts F5CAB2 Exam Questions

Page: 1 / 8 Total 72 questions

Want more questions? Get Premium Access.

Question 1

An application is configured so that the same pool member must be used for an entire session, as well as for HTTP and FTP traffic. A user reports that a session has terminated, and the user must restart the session. The BIG-IP Administrator determines that the active BIG-IP device failed over to the standby BIG-IP device. Which configuration settings should the BIG-IP Administrator verify to ensure proper behavior when BIG-IP failover occurs?

Correct Answer: D. Persistence mirroring and Match Across Services
Explanation:

In this scenario, two specific High Availability and Persistence requirements must be met to ensure session continuity during a failover.

Persistence Mirroring: By default, persistence records (which map a client to a specific server) exist only on the memory of the active BIG-IP. If a failover occurs, the standby unit has no knowledge of these sessions and will re-load-balance the client, likely to a different server. Enabling Persistence Mirroring ensures that the persistence table is synchronized in real-time to the standby peer.

Match Across Services: The requirement specifies that the session must persist across both HTTP and FTP. These are different Virtual Servers (and likely different ports). The Match Across Services setting in the persistence profile allows the BIG-IP to use the same persistence record for any Virtual Server that shares the same IP address and pool, regardless of the service port.


Question 2

A BIG-IP Administrator is conducting maintenance on one BIG-IP appliance in an HA Pair. Why should the BIG-IP Administrator put the appliance into FORCED-OFFLINE state?

Correct Answer: D. To terminate existing connections to Virtual Servers and prevent the appliance from becoming active
Explanation:

The Forced Offline state is a critical administrative tool used during maintenance to ensure a device remains in a non-functional state relative to the traffic group.

Preventing Active Status: When a device is in 'Forced Offline,' it is effectively disqualified from the HA election process. Even if the other peer fails, a device in Forced Offline will not become active. This is vital during maintenance (like firmware upgrades or hardware replacement) to prevent an unstable or half-configured device from attempting to process traffic.

Traffic Termination: Placing a device in Forced Offline triggers the system to stop accepting new connections and, depending on the configuration, can facilitate the termination of existing connections so that the administrator can perform work without the data plane actively utilizing system resources.

Persistence Handling: Unlike the 'Disabled' state, Forced Offline ignores persistence records, ensuring that no new traffic is steered to the device via session affinity.


Question 3

and their status/statistics]

To increase available bandwidth of an existing Trunk, the BIG-IP Administrator is adding additional interfaces. Which command should the BIG-IP Administrator run from within bash shell?

Correct Answer: D. tmsh modify /net trunk trunk_A interfaces add {1.3 1.4}
Explanation:

Configuring networking objects in BIG-IP requires using the correct TMSH module path and verb.

Module Path: Trunks are networking objects, so they reside under the /net module, not /sys.

Verb: Since the trunk already exists, the modify verb must be used to update its properties rather than create.

Syntax: The correct syntax to append physical interfaces to an existing trunk is tmsh modify /net trunk [name] interfaces add { [port list] }.

Data Plane Impact: Adding interfaces to a trunk (Link Aggregation) increases the total aggregate bandwidth available to the system and provides additional hardware redundancy.


Question 4

The BIG-IP Administrator wants to provide quick failover between the F5 LTM devices that are configured as an HA pair with a single Self IP using the MAC Masquerade feature. The administrator configures MAC masquerade for traffic-group-1 using the following command:

`tmsh modify /cm traffic-group traffic-group-1 mac 02:12:34:56:00:00`

However, the Network Operations team identifies an issue with using the same MAC address across multiple VLANs. As a result, the administrator enables Per-VLAN MAC Masquerade to ensure a unique MAC address per VLAN by running:

`tmsh modify /sys db tm.macmasqaddr_per_vlan value true`

What would be the resulting MAC address on a tagged VLAN with ID 1501? (Choose one answer)

Correct Answer: C. 02:12:34:56:05:dd
Explanation:

In BIG-IP high availability (HA) configurations, MAC Masquerade is used to speed up failover by allowing traffic-group-associated Self IPs to retain the same MAC address when moving between devices. This prevents upstream switches and routers from having to relearn ARP entries during a failover event, resulting in near-instant traffic recovery.

By default, MAC masquerade applies one MAC address per traffic group, regardless of how many VLANs the traffic group spans. This can create problems in some network designs because the same MAC address appearing on multiple VLANs may violate network policies or confuse switching infrastructure.

To address this, BIG-IP provides Per-VLAN MAC Masquerade, enabled by the database variable:

`tm.macmasqaddr_per_vlan = true`

When this feature is enabled:

BIG-IP derives a unique MAC address per VLAN

The base MAC address configured on the traffic group remains the first four octets

The last two octets are replaced with the VLAN ID expressed in hexadecimal

The VLAN ID is encoded in network byte order (high byte first, low byte second)

### VLAN ID Conversion:

VLAN ID: 1501 (decimal)

Convert to hexadecimal:

1501 = 0x05DD

High byte: 05

Low byte: DD

### Resulting MAC Address:

Base MAC: `02:12:34:56:00:00`

Per-VLAN substitution last two bytes = `05:DD`

Final MAC address:

`02:12:34:56:05:dd`

### Why the Other Options Are Incorrect:

A (01:15) -- Incorrect hexadecimal conversion of 1501

B (dd:05) -- Byte order reversed (little-endian, not used by BIG-IP)

D (15:01) -- Uses decimal values instead of hexadecimal

### Key BIG-IP HA Concept Reinforced:

Per-VLAN MAC Masquerade ensures Layer 2 uniqueness per VLAN while preserving the fast failover benefits of traffic groups, making it the recommended best practice in multi-VLAN HA deployments.


Question 5

An organization needs to deploy an HTTP application on a BIG-IP system. The requirements specify hardware acceleration to enhance performance, while HTTP optimization features are not required.

What type of virtual server and associated protocol profile should be used to meet these requirements? (Choose one answer)

Correct Answer: C. Type: Performance (Layer 4) Protocol Profile: fastL4
Explanation:

To select the correct virtual server type, an administrator must balance the need for L7 intelligence versus raw throughput and hardware offloading:

Performance (Layer 4) Virtual Server: This type is designed for maximum speed. It uses the fastL4 profile, which allows the BIG-IP system to leverage the ePVA (Embedded Packet Velocity Accelerator) hardware chip. When a Performance (L4) virtual server is used, the system processes packets at the network layer (L4) without looking into the application payload (L7). This fulfills the requirement for hardware acceleration and avoids the overhead of HTTP optimization features, which are not needed in this scenario.

Performance (HTTP) Virtual Server: While fast, this type uses the fasthttp profile to provide some L7 awareness and optimization (like header insertion or small-scale multiplexing). Since the requirement specifically states HTTP optimization is not required, the L4 variant is more efficient.

Standard Virtual Server: This is a full-proxy type. While it offers the most features (SSL offload, iRules, Compression), it processes traffic primarily in the TMOS software layer (or via high-level hardware assistance), which is 'slower' than the pure hardware switching path of the Performance (L4) type.

Stateless Virtual Server: This is typically used for specific UDP/ICMP traffic where the system does not need to maintain a connection table. It is not appropriate for standard HTTP (TCP) applications requiring persistent sessions or stateful load balancing.

By choosing Performance (Layer 4) with the fastL4 profile, the organization ensures that the traffic is handled by the hardware acceleration chips, providing the lowest latency and highest throughput possible for their HTTP application.


Question 6

The diagram below shows the TCP connection setup for an application.

Which of the following virtual server types applies? (Choose one answer)

Correct Answer: B. Forwarding IP virtual server
Explanation:

The diagram illustrates a specific TCP handshake sequence where the BIG-IP system acts as a transparent forwarder rather than a full proxy. The key indicators that identify this as a Forwarding (IP) virtual server are as follows:

Initial Packet Processing: The diagram explicitly states that the LTM evaluates the packet looking only at the destination IP address. This is the fundamental characteristic of a Forwarding IP virtual server, which uses the system's routing table to make forwarding decisions instead of load balancing to a pool of members.

Handshake Sequence: Unlike a Standard virtual server, which completes the three-way handshake with the client (SYN, SYN-ACK, ACK) before initiating a separate connection to the server, the Forwarding IP virtual server passes the client's original SYN packet directly to the destination node.

Response Timing: The BIG-IP system waits for the SYN-ACK from the destination node before it sends a SYN-ACK back to the client. It essentially 'passes through' the handshake signals while still maintaining a state entry in the connection table to track the flow.

Packet-by-Packet Logic: While it tracks the state, it does not perform address translation (unless SNAT is specifically configured) or deep packet inspection like a full proxy would.

Why other options are incorrect:

Standard virtual server: A Standard virtual server is a 'full proxy.' It would finish the handshake with the client first and only then open a second, independent TCP connection to the backend server.

Stateless virtual server: A stateless virtual server does not track connections in the connection table. The diagram shows the system meticulously passing sequence numbers ($seq\_num$) and acknowledgment numbers ($ack\_num$) between the two sides, which requires stateful tracking of the TCP flow.


Question 7

When using the setup utility to configure a redundant pair, you are asked to provide a "Failover Peer IP". Which address is this?

Correct Answer: B. an address of the other system in a redundant pair configuration
Explanation:

When establishing a redundant pair, each device must know where to send its health heartbeats and sync data.

The Peer IP: The Failover Peer IP is the IP address belonging to the other BIG-IP device in the HA pair. This is typically a34 Self-IP on a dedicated 'HA' or 'Internal' VLAN, or the Management IP.

Purpose: It identifies the destination for the 'Heartbeat' (the 'Are you alive?' check).

Setup Context: During the initial setup, you tell Device A to look for Device B at its 'Failover Peer IP,' and you tell Device B to look for Device A at its respective 'Failover Peer IP.'


Question 8

and their status/statistics]

A BIG-IP Administrator needs to connect a BIG-IP system to two upstream switches to provide external network resilience. The network engineer instructs the administrator to configure interface binding with LACP. Which configuration should the administrator use? (Choose one answer)

Correct Answer: D. A Trunk containing an interface connected to each switch.
Explanation:

In BIG-IP architecture, link aggregation and redundancy at Layer 2 are implemented using Trunks, not virtual servers or pools.

According to BIG-IP Administration Data Plane Concepts:

Interfaces are the physical network ports on the BIG-IP device

A Trunk is a logical grouping of multiple interfaces

Trunks can be configured to use LACP (Link Aggregation Control Protocol) to:

Provide link redundancy

Increase aggregate bandwidth

Allow automatic detection of link failures

VLANs are then assigned to the trunk, not directly to individual interfaces, once aggregation is in place

Correct Design for the Scenario:

To connect BIG-IP to two upstream switches with LACP:

One physical interface from BIG-IP connects to Switch A

Another physical interface from BIG-IP connects to Switch B

Both interfaces are placed into the same trunk

LACP is enabled on the trunk and on the switches

This configuration allows:

Traffic to continue flowing if one interface or switch fails

Proper LACP negotiation between BIG-IP and the upstream switches

Clean separation of responsibilities (Layer 2 handled by trunking, Layer 4--7 by virtual servers)

Why Option D Is Correct:

A Trunk containing an interface connected to each switch is exactly how BIG-IP implements LACP-based interface binding

The trunk handles link state, load distribution, and failover at the data plane

Why the Other Options Are Incorrect:

A & B -- Virtual servers operate at Layers 4--7 and have nothing to do with physical link aggregation or LACP

C -- VLAN IDs and MAC addresses are not configured inside a trunk definition; trunks aggregate interfaces, and VLANs are applied to trunks

Key Data Plane Concept Reinforced:

On BIG-IP systems, LACP is always configured on a Trunk, which aggregates physical interfaces to provide Layer 2 resiliency and bandwidth aggregation. Virtual servers and pools are not involved in physical interface binding.


Question 9

A standard virtual server has been associated with a pool with multiple members. Assuming all other settings are left at their defaults, which statement is always true concerning traffic processed by the virtual server?

Correct Answer: A. The client IP address is unchanged between the client-side connection and the server-side connection.
Explanation:

Understanding the default behavior of a Standard Virtual Server regarding address and port translation is fundamental to BIG-IP administration.

Source Address Translation (SNAT): By default, the BIG-IP system does not perform Source Address Translation (SNAT). This means that the packet's source IP address (the Client IP) remains preserved as it passes through the BIG-IP to the pool member. This is critical for backend servers to identify the original client for logging and security purposes. Therefore, the client IP address is unchanged between the client-side and server-side connections.

Destination Address Translation (DAT): By default, a Standard Virtual Server always performs Destination Address Translation. The BIG-IP system changes the destination IP from the Virtual Server's IP address to the IP address of the specific Pool Member selected by the load balancing algorithm. Consequently, the server-side destination IP is different from the client-side destination IP.

Port Translation: By default, Port Translation is enabled. If a Virtual Server is listening on port 80 and the selected pool member is configured for port 8080, the BIG-IP will translate the destination port. Even if the ports happen to be the same, the setting allows for change, whereas the default SNAT setting (None) ensures the client IP remains static.


Question 10

The BIG-IP Administrator wants to provide quick failover between the F5 LTM devices that are configured as an HA pair with a single-selfip using the MAC Masquerade feature for this quick failover and runs this command: tmsh modify /cm traffic-group traffic-group-1 mac 02:12:34:56:00:00 However, the Network Operations team has identified an issue with the use of the same MAC address being used within different VLANs. As a result, the administrator decides to implement the Per-VLAN Mac Masquerade in order to have a unique MAC address on each VLAN: tmsh modify /sys db tm.macmasqaddr_per_vlan value true. What would be the resulting MAC address on a tagged VLAN of 1501? (Choose one answer)

Correct Answer: C. 02:12:34:56:05:dd
Explanation:

According to F5 BIG-IP documentation regarding High Availability and MAC Masquerade behavior, the system allows for more granular control over Layer 2 addresses during failover events.

Standard MAC Masquerade: By default, when a traffic group is assigned a MAC masquerade address (like 02:12:34:56:00:00), the BIG-IP system uses that exact MAC address for all traffic associated with that traffic group across all VLANs. This ensures that upstream switches do not need to relearn ARP entries for the Virtual IP, but it can cause issues in environments where multiple VLANs share the same physical infrastructure or monitoring tools that flag identical MACs across segments.

Per-VLAN MAC Masquerade: When the system database variable tm.macmasqaddr_per_vlan is set to true, the BIG-IP system calculates a unique MAC address for each VLAN. It does this by taking the base MAC masquerade address configured in the traffic group and adding the VLAN ID (tag) to it.

Calculation Logic:

Base MAC: 02:12:34:56:00:00

VLAN ID: 1501

To find the suffix, the VLAN ID is converted from decimal to hexadecimal:

$1501$ in decimal = 05DD in hex.

The system then applies this offset to the last two octets of the base MAC address.

00:00 + 05:DD = 05:DD.

Result: The final MAC address for VLAN 1501 becomes 02:12:34:56:05:dd.

This ensures that every VLAN has a unique Layer 2 identity while still reaping the benefits of 'gratuitous ARP-less' failover provided by MAC masquerading.