When you create your vserver_forward you can limit it to which vlan its exposed to.
From your description is this correct?
LTM intA: 192.168.1.0/24 (VLAN1, connected to external-FW)
LTM intB: 172.16.5.0/24 (VLAN2, connected to internal-FW)
then how is VLAN3 connected (since you use terms like upstream firewall, FW and then just firewall - is it three different type of firewalls connected on each interface on your LTM)?
Could you perhaps setup a drawing of this and upload it to bayimg.com or such (and then put a link in here to this drawing)?