With the new appliance (central manager) you could control all the other NSM appliances.
the nice thing is that you can create pre and post rules for each firewall, this means you can force begin and end rules on every firewall (not even the local nsm admin can disable or delete these.
So look up the new features of the Central manager appliance and see if this could fix your problem.