you must have the check marks checked, otherwise tunneling will not work.
what you should do is have each security server configured with its fqdn , not the load balancer fqdn.
you still can use a load balancer but its only for the authentication process. once a user is authenticated he goes directlly to one of the security server.
I agree that vmware documentaion lacks on this subject.
let me know if that helps.