@manderson7 - the answer is in the docs, I missed it as we put in firewall requests for all of the ports necessary, but just found it. Maybe it will be of some help to you.

In the troubleshooting page for the F5 Big-IP addon, you see this:

http://docs.splunk.com/Documentation/AddOns/released/F5BIGIP/Troubleshooting

"Destination unreachable" errors

Ensure that you have opened port 443 in your firewall to enable F5 BIG-IP to communicate with the iControl API over SSL.

The above troubleshooting docs are vague and need to be updated to say something like it says on a previous page (take notice of where it says the collection takes place):

The Splunk Add-on for F5 BIG-IP *collects* performance data (system settings, server performance, and traffic statistics data) for F5 BIG-IP servers from iControl APIs over the network using a modular input. You can configure this input using Splunk Web on your heavy forwarder.

On the machine running your heavy forwarder, open port 443 to allow communication with F5 BIG-IP.

http://docs.splunk.com/Documentation/AddOns/released/F5BIGIP/Configureinputs

So, in summary, you have to open port 443 on the heavy forwarder as the source (the one doing the polling) to the F5.

A side note: In order to send the iApp info, you have to configure the HTTP Event Collector (HEC), create a token and put that token in the F5 - port 8088 will be opened on the heavy forwarder, so you'll have to have that port opened from the F5 to the heavy forwarder.

https://www.f5.com/pdf/deployment-guides/f5-analytics-dg.pdf