Hello friend!
In tunnel forwarding mode, APs encapsulate user data packets over a CAPWAP data tunnel and send them to an AC. The AC then forwards these packets to an upper-layer network.
In direct forwarding mode, APs forward user data packets to an upper-layer network without encapsulating them over a CAPWAP data tunnel.
In direct forwarding mode, all interfaces must allow all service VLANs. In tunnel forwarding mode, to prevent MAC address flapping, interfaces cannot allow service VLANs. You can refer to the link
https://support.huawei.com/enterprise/en/doc/EDOC1100102756Hope to help you!