Ubiquiti · UniFi

UniFi SSH Commands: Console, AP and Switch Diagnostics

Use the credentials belonging to the device you are opening. A UniFi console and an adopted access point can be managed from the same browser while using different SSH settings. A successful Site Manager login therefore does not establish which SSH password will work on an AP.

Scope: UniFi OS consoles, UniFi gateways, adopted UniFi APs and switches. Paths follow Ubiquiti's current documentation reviewed 2026-10-08; UI labels and available shell commands vary by software and hardware. Legacy USG is called out separately. Not EdgeRouter or EdgeSwitch CLI.

Start with the device's built-in Debug Console when it is available. In UniFi Network, select the device, open its settings and choose Debug. For SSH, enable or inspect console SSH under Control Plane settings; adopted network devices use the Network application's Device SSH settings. Record the exact model, firmware and management IP before collecting output.

Choose the correct target #

TargetLogin contextUseful first evidence
UniFi OS console or Cloud GatewayConsole SSH settings; root accountConsole health and support file
Adopted UniFi AP or switchNetwork device SSH credentialsDevice-specific logs and uptime in the UI
UXG gatewayroot username; managed device SSH passwordGateway-specific evidence
Legacy USGLegacy gateway CLILegacy show commands, not UDM commands
EdgeRouterSeparate EdgeOS platformUse the EdgeRouter reference pages

Read-only connection examples; replace addresses and usernames:

Choose the correct target
UniFi · Administrative workstation for SSH; target device shell for logs

Active test

Replace these example values: <console-management-ip>.

ssh root@<console-management-ip>
Active test

Replace these example values: <device-ssh-user>, <ap-or-switch-management-ip>.

ssh <device-ssh-user>@<ap-or-switch-management-ip>

Where the documented device log exists:

Choose the correct target
UniFi · Administrative workstation for SSH; target device shell for logs

Read-only
tail -n 100 /var/log/messages
Output may contain sensitive operational data.
Read-only
tail -f /var/log/messages

Press Ctrl+C to stop following the log.

Output may contain sensitive operational data.

Stop the live tail with Ctrl+C after reproducing the issue once. The first command provides recent context; the second lets you associate a new event with a deliberate test. A log line without a matching timestamp and device identity is difficult to compare with client behavior.

Interpret access failures #

An authentication rejection is different from a TCP connection timeout. For rejection, recheck the selected credential store and username. For a timeout, inspect the management route, device IP and access policy. For connection refused, first confirm that SSH is enabled on that particular target. Do not reset an adopted device merely because remembered default credentials fail.

If a command is unavailable, stop and identify the platform. Copying a USG or EdgeSwitch command into an AP shell does not make the command portable. Use the support-file workflow when the expected logging path is absent. Avoid editing provisioned configuration files during evidence collection: a diagnostic session should leave the controller's intended configuration intact.

When escalating, include the device role, exact command, full error, incident time and whether browser management still works. This is more actionable than reporting only that “SSH is broken.”

Sources

Documentation reviewed: 8 October 2026