CAP AX Client through Port Lock / Port Security

Good Afternoon sir, I want to ask, why does the client from my CAP AX access point have to pass through port security? because the client from CAP AC does not have this problem. In the old CAPsMAN the client connection is forwarded from the access point directly to the controller, not passing through the security port. Here’s a simple diagram of my problem. The option of opening the port security is not possible.
portsecurity.jpg

Possible reason:
Old capsman was able to use local or capsman forwarding.
Last part is a tunnel where all traffic from cap was first tunneled to controller before being handled on controller.
This bypasses your port security.

New capsman only supports local forwarding.
You can work around that situation using EOIP or so between cap and controller.