Hi, I had this issue recently when upgrading a HA pair. The active could reach the updates server fine, but passive failed. Easiest way around this without messing around with static arp entries is to just refresh and download the software you require on the Active firewall. When the prompt comes up to sync with HA make sure you check the box and click OK. Once this is downloaded on the active jump over to the passive firewall >software> hit refresh , it will fail...But notice at the bottom of the software list you will have the latest version of software to install. it will just say Unknown in the "release date" column and it should have the install button ready for you to upgrade the passive. Hope that helps. Owen.
... View more