Hi Joe, a few questions for you:
1) I assume that this is a 2 BIG-IP setup, that is, you are forwarding reverse proxy traffic from this external BIG-IP to a virtual server on an internal BIG-IP. Correct?
2) If 1 is true, then 172.21.x.x is the internal Front End virtual server listening on port 4443?
3) The iApp creates an iRule that only passes traffic for the host names that you enter in the Front End FQDN, Lync Mobility FQDN, and simple URLs fields. I see that you are using lyncdiscover.x.x for your Front End server pool FQDN, but usually that name is reserved for Lync mobile use. Is that the correct pool FQDN? You are trying to access the external VIP using an IP address, but that will not work because the iRule will not pass the traffic.
Have you checked out the deployment guide for the iApp: https://www.f5.com/pdf/deployment-guides/microsoft-lync-iapp-dg.pdf? It has more detailed information about the iApp and also some post-config steps that may be required, depending on your topology.
thanks
Mike