well, I believe I spoke too soon.
As soon as I put the forward option in, it appeared to send the traffic correctly.
However, as soon as we put the no-snat on, our reverse proxy health check in the F5 starts alarming with 503 error, and ultimately rips the reverse proxy out of the rotation.
I'm going to run some TCP dumps to take a look at the issue further. The problem seems to exist when the reverse proxy connects to the internal VIP, as it SNATS by default to a specific IP address. When we remove the SNAT, it seems to not be able to get there. Anyone have some thoughts?