The IP space being public or private shouldn't have any impact to LTM routing. Clients who want to use that VS to access the internal VLAN hosts will need a route for that subnet or those hosts pointing to the LTM self IP on their subnet.
If you configure a virtual server enabled on the inbound VLAN (external in your example), set the type to forwarding and have a route to the clients (or have them on the same VLAN as a self IP) TMM will allow clients to access internal VLAN hosts.
The port lockdown settings for a self IP won't come into play here. That's only for admin access to the BIG-IP through the self IP addresses.