If your Netscaler is located in the DMZ, you may find that STA traffic is not communicating correctly via the Netscaler NSIP.  You can create a Net Profile and have that traffic routed via a SNIP address instead.  Make sure to allow the ports via your Firewall before you do this from the SNIP address.  The following Citrix forum posting gives you an insight into a similar issue. 

https://discussions.citrix.com/topic/387333-different-source-ip-for-specific-lb-service/