Thanks Hamish. Yes the network VS has SNAT automap on (and yes sorry VLAN 700 is indeed 10.10.70.0):
virtual NETVIP1 { snat automap destination 10.10.60.0:any mask 255.255.255.0 ip protocol tcp rules IRULE1 profiles fastL4 translate address enable translate service enable }
If this looks correct on the F5 side then I'll dig more into the ASA config, though debugging on the ASA shows the ACL, xlate, etc are all working as expected.
The odd thing is that access through the ASA works fine for a host VS that points to one of the same back end servers, it just doesn't work for the network VS.
-Simon.