Forum Discussion
Just to clarify what's going on with the "virtual" command. The traffic never actually leaves the box when using this method. No reason to worry about it being unencrypted in transit. If you run a tcpdump, you can watch the transition from the first vip to the second, never exposed outside of the hardware.
tcpdump -s0 -ni0.0 -w /var/tmp/ host or host
https://devcentral.f5.com/wiki/iRules.virtual.ashx
Note: In version 9.4.0 and higher, 'virtual ' can be used to route the connection to another virtual server, without leaving the BIG-IP. This functionality did not exist in previous versions. In order to make this functionality work, one must precede the virtual command with an LB::reselect command if a pool member has already been selected.