I followed this article and for me after I browse to the virtual server and submitted the credentials in the login form (username/password), on backend, it is indeed hitting the pool member, but on the user side, it is prompting me with another credential popup for username/password.
NTP is fine.
time is in sync on all the three dog heads. (client, server, KDC).
DNS A, PTR records are in place. no duplicate SPN.
It was not working. Basically SSO is not triggering.
Finally I found the root cause. On the SSO object configuration for the username, article says to use "apm-kcd". But when I used it, it was not working. After changed it to host/apm-kcd.f5.demo SSO started working.