Thank you for posting in Microsoft Q&A forum.
Even though a secondary site extends the primary site, the primary site manages all of the clients.
Like Jason said, the clients must be able to communicate with the Primary Site Servers management Point as the clients will Contact that for registration, after that the clients will Contact the Proxy Management Point on the Secondary site. So you would have to open port 80 from the clients to the Management Point.
If the response is helpful, please click "Accept Answer" and upvote it.