Hi Fabio,
Both interfaces on the cluster members should have unique management IPs, different from the NSRP address and each other. The management IPs are not replicated between the cluster members and have unique physical MAC addresses while NSRP IP is mapped to a virtual MAC address.
If you can reach both devices using ssh, everything is correctly configured. The web interface should also work.
I may assume that both cluster members are not in sync. Check it using "exec nsrp sync global-config check-sum".
The interfaces on the backup device are normally in the status "down" (logically). You can change this by issuing the command "set nsrp link-up-on-backup". The interfaces get status "Inactive". But interfaces that do not have specific management IPs, different from the NSRP IP and each other, stay in status "Down". Inactive interfaces can send icmp requests from the mgmt ip if ip tracking is configured and also negotiate VPN SAs.
You can ping mgmt IP of the master from the backup device but not vice-versa. If a ping request is sent from the master member, it has the NSRP IP address as it's source. The backup member does not accept such a packet. I suppose this is per design so.
There is a limitation in using ping on the backup member: "ping <IP>" works but "ping <IP> from ethx/y" does not. The error message "Interface ethernetx/y is inactive or down" is generated instead.
I do recommend to use MGT zone for the inhouse clusters and map it to a dedicated VR. Each MGT interface uses a single IP, both for addressing and the management, they are always "Up" and can reach each other without any limitations.
Use "get log self" to check the connections terminated on the FW interfaces. Issue "get firewall" to see what is logged. The output may look this way:
Log Self for IKE : Off
Log Self for SNMP: Off
Log Self for ICMP: Off
Log Self Deny: On
Log Self Deny exclude Multicast: On
Log Self for TELNET : Off
Log Self for SSH : Off
Log Self for WEB : Off
Log Self for NSM : Off
And, finally, use "debug flow basic" if the log records are not very informative.