For all interested parties:

After a support call to Palo Alto, it was determined that a "feature"(not a 'bug") that is "by design" was causing my issues.  Palo Alto says it is too costly to fix since there is a reasonable workaround.  If enough people complain to their SE, then maybe PA will fix the issue, which is still present in the new OS 4.0.x.

The fix was to add static ARP entries for each firewall's management interface in the layer3 sub-interface of the physical internal interface.

Once the ARP entries went in, my passive firewall was able to reach out to the Internet for PaloAlto updates.

Hope this helps!


