There's no a correct answer in the abstract. What drove the decision to have all nodes load balanced on a single VP then only load balance to the load VP on the RIMs? That being said, I don't see why you'd want to only distribute app consumption for a single point of entry.
Taking a step back. It looks like you have 3 proxy services. For there to be single entry point you would want to use a network load balancer or similar application to distribute the load between the different proxies. Something diagrammed like this:
Since each proxy service lives on a different server (e.g. server1, server2, server3), then users who access https://server1.company.com will use server1's proxy alone.
Back to the load balancing configs, having all engines load balanced to all is needed for your goal.
That being said, without something distributing the authentication across servers, those RIM proxies don't accomplish much in the abstract.