Best practice, is to fail traffic to the passive as the first step after disabling pre-empt(personally I have it off all the time anyway.) Then step through each iteration, switching firewalls at each step to confirm the upgrade is successful and traffic still passes. From what you say you have upgraded the passive all the way in one go. You could disable pre-empt now and fail the traffic over and see if it works but your more likely to see and issue. Better option would be to downgrade the passive and then fail over to it and do one step at a time on each. That way they are only ever one version different be it Major, Minor or Increment.
... View more