# Application Layer Gateway
Application Layer Gateway is a protocol, standard, or security technology recorded in [[Scanned_20260730-1706|Scanned_20260730-1706]]. In the reconstruction, An ALG inspects application protocols that embed addresses, ports, or secondary-flow negotiation in payloads, then opens temporary state or rewrites fields so traffic can traverse NAT/firewalls.
## Historical and Technical Context
An [[Application Layer Gateway|ALG]] inspects application protocols that embed addresses, ports, or secondary-flow negotiation in payloads, then opens temporary state or rewrites fields so traffic can traverse NAT/firewalls. Juniper documents that predefined services map to Layer 7 applications and that ALGs are bound to services such as FTP and RTSP ([Juniper ALG overview](https://www.juniper.net/documentation/us/en/software/junos/alg/topics/topic-map/security-introduction-to-algs.html)). The notebook correctly distinguishes Layer 4 service identification from Layer 7 application behavior, although its multicast/range notation is rough and should not be treated as a precise routing table.
## Role in Scanned_20260730-1706
The author is building a conceptual model of how Junos security policy crosses zones: a static policy identifies the service, while an ALG dynamically creates state for application-specific secondary traffic.
## Notebook Evidence
- [[Scanned_20260730-1706|Scanned_20260730-1706]], PDF page 25: Application Layer Gateway concept.
**Evidentiary status:** The page occurrence and transcription are notebook evidence. Technical identification follows the source reconstruction’s cited research. Co-occurrence does not by itself prove ownership, deployment, or a direct operational relationship.
## Relationships and Overlays
Application Layer Gateway is linked to the notebook source and its source-specific indexes; no additional page-level relationship is asserted.
## Cross-Notebook Significance
This note supplies a concrete network-policy or evidence mechanism beneath the AIOps, security-operations, and governance concerns in [[Scanned_20260730-1802|Scanned_20260730-1802]]. It shows how dynamic state is created, observed, and retained at the protocol boundary.
## Missed Signals and Open Leads
“BBS Infrastructure,” “0x0 null,” and the written address ranges need the originating Junos screen or manual page to resolve.
## Sources
- [[Scanned_20260730-1706|Scanned_20260730-1706]], especially PDF page(s) 25.
- `Scanned_20260730-1706.pdf`, cited as a plain archival filename; the PDF is not linked from `wiki-notes`.
- External research citations used for identification remain preserved in the source reconstruction.
- [Juniper ALG overview](https://www.juniper.net/documentation/us/en/software/junos/alg/topics/topic-map/security-introduction-to-algs.html)