01 — All Editions
Content Switching — Virtual Server Engine
NetScaler's content switching engine evaluates inbound HTTP/HTTPS requests against policy expressions — URL path, hostname, headers, query strings, HTTP method, source IP — and routes them to the appropriate backend service group. A single NetScaler VIP can front multiple discrete backend applications, each with its own load balancing pool, health monitors, SSL profile, and WAF policy.
Traffic Routing
02 — All Editions
Policy Engine — Citrix Policy Language (CPL)
NetScaler's Advanced Policy engine evaluates requests using a powerful expression language covering HTTP attributes, SSL parameters, client IP, TCP properties, and custom headers. Policies can rewrite URLs, inject or strip headers, enforce authentication, redirect traffic, compress responses, or apply rate limits — all without modifying backend application code.
Advanced Policy
03 — Premium / Advanced
Web Application Firewall (WAF)
NetScaler's WAF inspects HTTP/HTTPS traffic against OWASP Top 10 attack categories — SQL injection, cross-site scripting, buffer overflow, command injection, XML/JSON attacks, form field violations, and cookie tampering. Protection profiles operate in Learn mode (building a positive security model) or Enforce mode (blocking violations in real time).
OWASP Top 10
04 — Premium / Advanced
Bot Management
Identifies and classifies inbound traffic as human, known good bot (search engines), or malicious bot using device fingerprinting, TLS fingerprinting, rate analysis, CAPTCHA challenges, and IP reputation feeds. Malicious bots are blocked or trapped. Good bots are whitelisted. Human sessions proceed with zero friction — protecting against credential stuffing, scraping, and DDoS amplification.
Bot Detection
05 — All Editions
SSL/TLS Termination & Offload
NetScaler terminates SSL/TLS at the edge, decrypts traffic, applies WAF and policy inspection, then re-encrypts (or sends plaintext) to backend servers. This offloads computationally expensive cryptographic operations from application servers, improves backend performance, and enables deep packet inspection of HTTPS traffic that would otherwise be opaque at the network layer.
SSL Offload
06 — All Editions
Rate Limiting & DDoS Mitigation
Responder and Rewrite policies combined with connection throttling allow granular rate limiting per source IP, per URL, per user, or per session token. SYN flood protection, connection table limits, and TCP connection rate controls provide L4-level DDoS mitigation. Combined with Bot Management, NetScaler absorbs volumetric attacks before they reach backend infrastructure.
DDoS Protection