To my knowledge, there's no way to remove the firewall function from the MR traffic processing chain. I'm guessing the SSID in question may be configured in NAT mode (because the default Destination:Local LAN is a deny - that mode is designed for Guest users) You can, of course, set that to Allow but, if you want to use the most 'natural' setup, you would use bridge mode, for the SSID (configured under Wireless > Acess control). For 'Dry' you definitely don't want the clients behind a NAT.
As the question relates to MR Access Points, I'd suggest this thread be moved to Wireless LAN