The IPSEC ALG solves a specfic problem. You only need this if you have a VPN appliance behing the SRX getting a NAT from the SRX AND the appliance does NOT support NAT-T.
If you device has NAT-T support and you configure NAT-T on the tunnel you do NOT need the ALG.