When the tunnels are built on Check Point gateways managed by these management servers, this is correct. You cannot run management traffic over a tunnel that is managed by the same management server, think about it, when something fails on that tunnel, how will you be able to correct it?
For Management HA the ports used could be excluded from the Implied rules but the point is that 2 of these ports are also used in the communication between management and gateway.
The ports are 18221, 18211 and 18192 and the latter 2 are also used between GW and management.
Regards, Maarten