If you are strictly deploying LTM, you'd really want to put it behind your perimeter security devices. If you enable AFM, you will have a rich stateful firewall that can be placed on the Internet edge. If you are going to use load balancing on the F5, I personally like to have the F5 "present" on the server VLAN so that F5-to-pool-member communications are strictly layer 2. This helps to eliminate any MTU, tagging, etc. that could happen to load balanced traffic before it actually gets to the back end server, which greatly helps when troubleshooting.