I just want to share about this implementation,
SLB F5 has to be configured to forward http n https traffic from clients to Web server, and for secure connection we need to configure App server to force connection using https. Then certificate must be installed on web server side and can't be on SLB F5.
The rest settings of BPM Portal cluster are the similar if you are using different SLB.
Guys, you can message me if you need more detail regarding to this kind of implementation.
Rgds,