Hello Gary,
Thanks for posting. Have you confirmed that the Zone based firewall is the one causing the problem? Would you please enable the ip inspect log drop-pkt and identify if there is any packet being dropped from the microsoft servers?
I would like to know also what ports is being used by this MS update so if there is any inspection that may be causing a problem we can turn it off.
Let me know.
Mike
Mike