Kubermatic branding element

Load balancer migration Part 2: The cloud-native NetScaler alternative

Yellow fiber optic patch cables connected to blue LC adapters on a network patch panel

Migrating away from NetScaler (formerly Citrix ADC) to an alternative is a conversation happening in IT departments globally. For years, NetScaler has been a powerhouse in enterprise networking and VDI environments. But infrastructure has changed. As organizations embrace Kubernetes and multi-cloud, many are finding that traditional appliance-based load balancers are no longer the best fit.

Recent high-profile security vulnerabilities, unpredictable licensing changes under new corporate ownership, and the sheer complexity of legacy monolithic appliances have forced Platform Engineering and IT teams to evaluate their options. What they are discovering is that the future of application delivery looks very different from the past.

A brief history of NetScaler vs. KubeLB

NetScaler and KubeLB represent two vastly different eras of application delivery and architecture.

NetScaler: The legacy enterprise titan

NetScaler was designed for traditional enterprise environments, offering complex traffic management, content switching, and delivering virtual desktop infrastructure (VDI). While highly capable, it is a heavyweight, monolithic appliance (hardware or virtualized) that demands specialized knowledge to configure, patch, and maintain. In a dynamic, containerized world, it often acts as a chokepoint rather than an enabler.

The cloud-native disruptor

Kubermatic KubeLB was engineered specifically for the Kubernetes and multi-cloud era. Instead of a monolithic bottleneck, KubeLB is distributed and cloud-native. Leveraging industry-standard open-source technologies like Cilium and Envoy, it provides centralized Layer 4 and Layer 7 load balancing across multiple clusters and environments. It brings agility, declarative configuration, and automated multi-tenancy right out of the box.

A market shift: Why are so many leaving NetScaler?

If NetScaler has been a staple for so long, what is driving the mass migration?

1. The vulnerability crisis and patching fatigue

In recent years, critical NetScaler vulnerabilities (such as “Citrix Bleed”) have left organizations exposed to severe security risks. Emergency out-of-band patching of complex, customer-managed NetScaler appliances causes massive operational headaches and planned downtime. IT teams are tired of their load balancers becoming a security liability.

2. Licensing uncertainty and cost

Following changes in corporate ownership, many Citrix/NetScaler customers have faced shifting licensing models, forced subscription transitions, and unpredictable cost increases. KubeLB, built on open-source principles, offers a transparent, scalable model that aligns with cloud-native growth without the lock-in of proprietary hardware.

3. Friction in Kubernetes environments

NetScaler’s integration with Kubernetes (via CPX or Ingress Controllers) often feels bolted-on. Managing dynamic pod IPs, ephemeral workloads, and automated service discovery through a legacy ADC interface creates friction for developers. KubeLB natively integrates with Kubernetes Custom Resource Definitions (CRDs), allowing platform engineers to manage networking using the same declarative workflows they use for their applications.

The KubeLB alternative

For organizations migrating workloads to containers and looking for a modern networking stack, KubeLB provides a compelling path forward:

1. Simple multi-cluster management

Unlike managing individual NetScaler high-availability (HA) pairs, KubeLB uses a Hub-and-Spoke architecture. A central Management Cluster intelligently provisions and routes traffic to hundreds of decentralized Tenant Clusters, providing a single pane of glass for your entire application delivery network.

2. Declarative networking with Gateway API

Say goodbye to complex CLI commands and proprietary policy expressions. KubeLB fully embraces the Kubernetes Gateway API. Traffic routing, SSL termination, and header manipulation are defined via YAML, integrated directly into your CI/CD pipelines, and instantly applied across the fleet.

3. Future-proofed for AI

Modern infrastructure needs more than just traditional load balancing. KubeLB includes an integrated AI Gateway designed to route, secure, and monitor Large Language Model (LLM) traffic, ensuring your platform is ready for the next generation of AI-driven applications.

4. Routing traffic to legacy VM workloads

Moving away from NetScaler doesn’t mean you need to containerize everything overnight. KubeLB serves as a powerful bridge between the old and the new. It can completely replace legacy VM workloads while natively routing traffic to traditional virtual machines and bare-metal servers. This allows you to unify application delivery for both legacy monolithic applications and modern microservices under one cloud-native control plane.

NetScaler vs. KubeLB: Feature comparison

FeatureNetScaler (Citrix ADC)Kubermatic KubeLB
Core ArchitectureProprietary monolithic appliance (MPX/VPX)Cloud-native, distributed (Cilium + Envoy)
Configuration MethodologyCLI, GUI, proprietary Nitro APIDeclarative Kubernetes CRDs (GitOps ready)
Traffic ManagementContent Switching, AppExpert policiesGateway API (HTTPRoute, TCPRoute), Ingress
VM SupportStandardReplaces VM workloads & routes to VMs/bare-metal
Multi-TenancyAdmin Partitions / SDX (Hardware slicing)Native cluster isolation (Hub & Spoke)
AI Workload SupportNot natively specializedBuilt-in AI Gateway for LLM traffic

Terminology comparison: Translating NetScaler to KubeLB

If your team is fluent in NetScaler, here is how the concepts map to the cloud-native world of KubeLB:

NetScaler TerminologyKubeLB / Cloud-Native Terminology
vServer (Virtual Server) / VIPLoadBalancer IP / Gateway Listener
Service Group / ServicesKubernetes Services / Endpoints
Content Switching PoliciesGateway API HTTPRoute rules
NetScaler ADM (Application Delivery Management)KubeLB Management Cluster

How to migrate away from NetScaler

Moving away from NetScaler is best handled in phases. Because KubeLB integrates at the Kubernetes cluster level, you can begin by routing new containerized applications entirely through KubeLB using Gateway API. Over time, as legacy monolithic applications are refactored into microservices, or kept as VMs routed via KubeLB, their traffic can be seamlessly migrated over, allowing you to gradually decommission your NetScaler appliances and reduce your attack surface and licensing costs.

Learn more

Abubakar Siddiq Ango

Abubakar Siddiq Ango

Senior Developer Advocate

Kubermatic named in the 2025 Gartner® Magic Quadrant™ for Container Management

Access the Report

Empower Your Business with Cloud Native Labs Consulting Services, Accelerators and Trainings

Discover More