Internal traffic is recommended to go from Horizon Client to VDI Agent directly, without gateway configured on the connection servers.
When you are using Security servers, you have to pair connection server with them and enable all the gateways for external access, so you cannot point to the internal connection servers for that reason.
I recommend you using Access point instead of Security Servers, it does not need to be paired and gateways are disabled on the connection servers.