mgmt interface configuration
I have used mgmt ports on fgt's in the past without problems: I have two HA clusters, each one of them has their own IP in one and the same network and I used NAT in the firewall rule to get access to the other cluster which was not the main cluster. In this configuration I could manage every one of the four devices separately and this has been useful and needed to get the HA fixed when it has broken sometimes. That was so in 5.4.
After upgrading to 6.4 I see that something has changed. Recently I restored a broken HA cluster and noted that the mgmt1 interface shows its address with red background and mentioning there an overlapping address. Yes, I needed another VLAN interface in the main cluster in the same mgmt subnet to make the NAT work in the firewall rule.
Is it possible to get the management working without a NAT-rule? There's information here: https://docs.fortinet.com/document/fortigate/6.4.4/administration-guide/313152/out-of-band-management-with-reserved-management-interfaces
But one thing is unclear and even confusing: what is the gateway in "management interface reservation" configuration? Where is it? It is not shown in the diagram. A random IP in the same network which doesn't even have to exist? If overlapping of subnets is not allowed, it can't be in the same unit/VDOM if it is meant to be a real address. (Do I need a separate FGT to manage the cluster?...) Also, there is no explanation of how the 10.11.101.100 works in that diagram that is common to both units and that is used to configure the new separate addresses for units. And the explanation for "Destination subnet", which is "Optionally, enter a Destination subnet to indicate the destinations that should use the defined gateway.", doesn't really tell me anything what is it really and what is it used for. Then there is "set ha-direct enable" option but no good explanation, what is this and for what purpose is it needed.
Has anybody got working the mgmt of HA cluster members without overlapping subnets (in one of the VDOMs of the same device) and without a firewall rule with NAT? What is the secret here?
