1. If you are coming from the same internet connection users are using to get in via SSL VPN, it's not out-of-band but in-band. "dedicated" management interface is isolated from other part (root).
2. I would suggest setting an interface IP on ssl.root and enable SSH or HTTPS to admin, which would be the closest to out-of-band if you would ignore it's sharing the same internet circuit with users. No policy is necessary for this.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.