Well done.
If you want some background and extra info:
1.
R82 has enhanced the Management behind NAT configuration options (see link below and screenshots attached):
https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Cont...
2.
Apply for Security Gateway Control Connections
That does not really expose the management server and ports, but I understand what you mean.
Below is the official description, but a good way to understand that option better is a specific scenario.
In the scenario the management server is positioned directly behind one of the managed gateways (or clusters) and uses that gateway to reach the rest of the managed gateways, but the management server is NATed behind the local gateway.
All of the managed gateways 'learn' about the real and NAT IP addresses of the management server (as a result of the policy installations).
The local gateway actually applies the NAT on the management traffic (control connections (policy install and log and status sending etc.)), as long as that option is checked.
The local gateway does not NAT management traffic that is directed to itself (for example, the local gateway getting a policy installation from the management server or sending logs and status messages back to the management server), assuming it is on the same network (probably there to secure the management server).
So the option is a way of educating the gateways about the IP addresses of the management server and then they can use that for internal communications/control connections.
"
- This option performs NAT on VPN control connections to and from this object. This makes it possible to install a policy or collect logs across a NAT gateway. This object must be either a Security Management server or a Log Server.
"