Performing a Firmware Update on HA Pairs
- Last Updated: September 2, 2026
- 2 minute read
- MOVEit WAF
- Documentation
We recommend performing firmware updates outside of working hours. This ensures there is no interruption to client connectivity. If it has to be done during working hours, we recommend scheduling a maintenance window.
Firmware updates on a High Availability (HA) pair are not automatic — you must manually upload the firmware file and start the update on each unit individually, one at a time, using the steps below.
We recommend updating the passive unit first and then updating the active unit. This causes only a single failover and minimal downtime, and is the preferred option for most customers. While this procedure does leave the currently passive MOVEit WAF unit as the active MOVEit WAF unit going forward, this usually has no consequences in most customer environments. However, it is also possible to update the currently active unit, failover to the passive unit, update the passive unit, and then failover to the originally active unit.
To update the firmware on a HA pair using the recommended method; perform the following steps using the shared IP address:
- On the passive MOVEit WAF unit (we will refer to this MOVEit WAF unit as B), go to System Configuration > System Administration > Update Software, click Choose File, browse to and select the patch file, and click Update Machine to start the update.
- When the update is complete, reboot B.
- When unit B is back up, repeat the same manual process to upload the firmware patch file and update the firmware on the active unit (we will refer to this unit as A).
- When the update is complete, reboot A. Now B becomes active.
- Ensure B is handling traffic.