Moving comment to answer:
would need more details to be helpful. what protocol? you can have a standard 0.0.0.0: vip and could apply an iRule w/ a datagroup or a sideband service that has the list of internal IPs allowed and use a simply forward statement.
WRT to security of a forwarding vip or a standard vip-there's no difference in security posture. Standard vip just needs a destination, whereas a forwarding vip will consult the routing table. You can do more with a standard vip wrt to security because you can apply profiles to get at the higher layers, but "just as" is no more secure than a forwarding vip.