# Application Layer Gateway Application Layer Gateway is a protocol, standard, or security technology recorded in [[Scanned_20260730-1706|Scanned_20260730-1706]]. In the reconstruction, An ALG inspects application protocols that embed addresses, ports, or secondary-flow negotiation in payloads, then opens temporary state or rewrites fields so traffic can traverse NAT/firewalls. ## Historical and Technical Context An [[Application Layer Gateway|ALG]] inspects application protocols that embed addresses, ports, or secondary-flow negotiation in payloads, then opens temporary state or rewrites fields so traffic can traverse NAT/firewalls. Juniper documents that predefined services map to Layer 7 applications and that ALGs are bound to services such as FTP and RTSP ([Juniper ALG overview](https://www.juniper.net/documentation/us/en/software/junos/alg/topics/topic-map/security-introduction-to-algs.html)). The notebook correctly distinguishes Layer 4 service identification from Layer 7 application behavior, although its multicast/range notation is rough and should not be treated as a precise routing table. ## Role in Scanned_20260730-1706 The author is building a conceptual model of how Junos security policy crosses zones: a static policy identifies the service, while an ALG dynamically creates state for application-specific secondary traffic. ## Notebook Evidence - [[Scanned_20260730-1706|Scanned_20260730-1706]], PDF page 25: Application Layer Gateway concept. **Evidentiary status:** The page occurrence and transcription are notebook evidence. Technical identification follows the source reconstruction’s cited research. Co-occurrence does not by itself prove ownership, deployment, or a direct operational relationship. ## Relationships and Overlays Application Layer Gateway is linked to the notebook source and its source-specific indexes; no additional page-level relationship is asserted. ## Cross-Notebook Significance This note supplies a concrete network-policy or evidence mechanism beneath the AIOps, security-operations, and governance concerns in [[Scanned_20260730-1802|Scanned_20260730-1802]]. It shows how dynamic state is created, observed, and retained at the protocol boundary. ## Missed Signals and Open Leads “BBS Infrastructure,” “0x0 null,” and the written address ranges need the originating Junos screen or manual page to resolve. ## Sources - [[Scanned_20260730-1706|Scanned_20260730-1706]], especially PDF page(s) 25. - `Scanned_20260730-1706.pdf`, cited as a plain archival filename; the PDF is not linked from `wiki-notes`. - External research citations used for identification remain preserved in the source reconstruction. - [Juniper ALG overview](https://www.juniper.net/documentation/us/en/software/junos/alg/topics/topic-map/security-introduction-to-algs.html)