While performing a sync to peer when performing a software or dynamic update does work around the issue of a passive device in a HA pair not being able to get the updates, it is not best practice and it can expose you to split brains when your HA pair is under heavy loads. Configuring static ARPs on the internal L3 interfaces allows both PAN devices to access PANs update servers without increasing the risks of split brains.
I have the same issue, with an HA. Currently Active can update its content updates, but Passive can't update them. I have a question, about your workaround.
When you said "configure the ARP entries", do your refer to add the MAC address, of each MGT interface, in all Layer 3 interfaces that I have configured?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!