In addition, concerning your question number 3. It looks to me a configuration issue. With management Plane enabled, you have two VRFs, one of them taking care of FW operations and connectivity, and the MP in charge of admin/log/management traffic. As you mentioned, both planes have separate routing tables and DNS definitions. When MP admin traffic stays internal, there is no issue. Once you need to reach out to Internet, there is most probably a routing issue, since MP should actually pass through the data plane to reach Internet IPs.
Disamping MP separation makes sense, and you need just to figure out why you lose direct internet connectivity. My bet is, that is because you lose DNS and routing settings from MP, and you just need to re-create them.
That said, it is not exactly easy to provide you with any guidance without details.