Start with the device's built-in Debug Console when it is available. In UniFi Network, select the device, open its settings and choose Debug. For SSH, enable or inspect console SSH under Control Plane settings; adopted network devices use the Network application's Device SSH settings. Record the exact model, firmware and management IP before collecting output.
Choose the correct target #
| Target | Login context | Useful first evidence |
|---|---|---|
| UniFi OS console or Cloud Gateway | Console SSH settings; root account | Console health and support file |
| Adopted UniFi AP or switch | Network device SSH credentials | Device-specific logs and uptime in the UI |
| UXG gateway | root username; managed device SSH password | Gateway-specific evidence |
| Legacy USG | Legacy gateway CLI | Legacy show commands, not UDM commands |
| EdgeRouter | Separate EdgeOS platform | Use the EdgeRouter reference pages |
Read-only connection examples; replace addresses and usernames:
Choose the correct target
UniFi · Administrative workstation for SSH; target device shell for logs
Replace these example values: <console-management-ip>.
ssh root@<console-management-ip>Replace these example values: <device-ssh-user>, <ap-or-switch-management-ip>.
ssh <device-ssh-user>@<ap-or-switch-management-ip>Where the documented device log exists:
Choose the correct target
UniFi · Administrative workstation for SSH; target device shell for logs
tail -n 100 /var/log/messagesOutput may contain sensitive operational data.tail -f /var/log/messagesPress Ctrl+C to stop following the log.
Output may contain sensitive operational data.Stop the live tail with Ctrl+C after reproducing the issue once. The first command provides recent context; the second lets you associate a new event with a deliberate test. A log line without a matching timestamp and device identity is difficult to compare with client behavior.
Interpret access failures #
An authentication rejection is different from a TCP connection timeout. For rejection, recheck the selected credential store and username. For a timeout, inspect the management route, device IP and access policy. For connection refused, first confirm that SSH is enabled on that particular target. Do not reset an adopted device merely because remembered default credentials fail.
If a command is unavailable, stop and identify the platform. Copying a USG or EdgeSwitch command into an AP shell does not make the command portable. Use the support-file workflow when the expected logging path is absent. Avoid editing provisioned configuration files during evidence collection: a diagnostic session should leave the controller's intended configuration intact.
When escalating, include the device role, exact command, full error, incident time and whether browser management still works. This is more actionable than reporting only that “SSH is broken.”
Sources
Documentation reviewed: 8 October 2026