Another Problem with the up2date of an HA Pair is that the Slave updates directly from the Internet.
The upload of the up2date-Package to the Master is only for the Master not for the Slave. So if your UTM is not directly connected to the Internet you may have a Problem.
A Firewallrule wich allows the Contact from the UTM to the Astaro/Sophos Update Servers is not enough, it seems there are Servers with dynamic Names/adresses in the Cloud wich have to be allowed to.