The management interface of the vSEC, or CloudGuard is exposed to the Internet by design and is getting assigned the static public IP as a normal part of the installation process.
In a sense, it is no different from any remotely managed gateway, such as those located in a bank branches.
When Management Server connecting to it initially, SIC takes care of establishing secure communication channel for management and log shipping.
Management server itself though, should be statically NATed on your local gateway to a public IP.
Since it'll be the only management server connected to the gateway, it will automatically be defined as a target for logging.
If you have separate log servers, SmartEvent appliances, etc., situation may be slightly more complex.
Cheers,
Vladimir