Ping request to Standby Firewall backup IP configured under HA | Monitoring doesn't respond to traffic initiated from WAN side of the Active Firewall.
If we ping the backup IP within the LAN side then we see backup firewall responds to the echo requests but when traffic comes with a source IP address other than LAN subnet where monitoring for Primary and secondary IP addresses has been configured, then it doesn't respond as its a standby unit in HA pair.
Standby Firewall responds to the traffic arriving on its X0 interface so we can perform source NAT translation on the active firewall for the Traffic coming from WAN side destined for Standby Firewall back up with its Primary X0 IP so when it arrives at the standby firewall it will appear as local traffic and standby firewall will send it back to the active firewall and then it will forwarded back to where it had come from.
Two NAT policies will be required on active firewall which will allow access to the standby Unit (Primary of Secondary) IP when traffic is coming from a subnet other than LAN.
CAUTION: Export the Current Firewall settings by navigating to System | Settings | Click on "Export Settings" button.
It's also highly recommend to have a backup which can be used a one touch restore point. Plan and arrange a maintenance window before making the required changes.
This article assumes that Monitoring for X0 has been configured under HA | Monitoring, and Primary and Secondary IPs are configured.
