Not sure if I am getting a clear picture without desired state topology diagram.
That being said, if I understand it correctly:
1. Your Site B cluster was previously managed via private IP
2. It is now must be managed by the management server located at the same site via this private IP
3. You now are shifting management function to the site A MDS
4. There is a VPN present between Site A and Site B gateways or clusters
5. Both site's gateways or clusters will be managed by the same MDS and, possibly same CMA
The best approach, IMHO, will be to change the management IP of the HA cluster and its members in site B to its public VIP.
Note that this will necessitate the re-establishing SIC with the gateways.
So long as you Encryption Domain in Site B is properly defined and DOES NOT include cluster's public IP, the management traffic between CMA in Site A and the Cluster in Site B will not be going over the VPN, but will be secured by SIC.