Hmm..
If your firewall is expecting the LTM to ARP respond for the network VS, then it's not configured right. The only reason it would be doing that is if the firewall considered the network represented by the network VS to be directly attached. WHich it isn't (Because if it was, you wouldn't need a network VS in the first place).
You either need to use a network VS and a ROUTE from the firewall TO the network VIA the BigIP floating IP, OR you use the network range on that VLAN and configure individual VS's on it... Not both.
Any chance that you could attach a LOGICAL diagram showing where the networks and vans actually exist?
H