For an Internet Access Gateway operative between an area network and a
public network, managing dynamic network sessions therebetween whereby a
primary server on the public network in a primary session with a client
of the area network initiates an additional session with an additional
server on the public network, for which an unexpected data packet
received at the gateway from the additional server is associated with the
primary session, and accordingly allowed access to the area network
through the gateway, provided the gateway received the data packet at an
input port exceeding 1023, the additional session comprises a pre-defined
Session Triggering Event, and at least one internal network component of
the area network indicates willingness to receive the data packet.
Wherefore, a preferred Application Level Gateway is thereby provided for
firewall and NAT implementations to enhance network security.