Home / Blog Center / Tips & Tutorials /

How to Enable SSH and Get Root Access on UGREEN NAS

How to Enable SSH and Get Root Access on UGREEN NAS

02/12/2025

You can enable SSH from Control Panel > Terminal in UGOS Pro and connect from Windows, macOS, or Linux. Sign in through SSH with a UGOS Pro administrator account, then run sudo -i when you need root privileges.

Because a root shell can change or delete system files, restrict SSH to trusted devices, keep the security level set to High, and disable the service when you finish.

enable ssh service

Before You Enable SSH on UGREEN NAS

Prepare the following before opening a Terminal session:

  • The username and password of a UGOS Pro administrator account
  • The local IP address of the NAS
  • A computer connected to the same trusted network
  • Continued access to the UGOS Pro web interface
  • A clear record of the command or configuration you intend to change

Create an independent copy of important files before making system-level changes. Our guide to choosing a NAS backup strategy explains how to separate RAID availability, local backup, and off-site recovery.

SSH access itself is an administrative feature. Changes to system files, permissions, services, or package dependencies can affect UGOS Pro stability, security, and future updates.

How to Enable SSH in UGOS Pro

  1. Sign in to UGOS Pro with an administrator account.
  2. Open Control Panel.
  3. Select Terminal.
  4. Enable SSH.
  5. Keep the default port or enter a custom port number.
  6. Set an automatic disable time so the service does not remain available longer than necessary.
  7. Open the advanced SSH settings.
  8. Keep the security level set to High.
  9. Restrict the permitted access range to the local network when possible.
  10. Enable SFTP only if you need to transfer files through the SSH service.
  11. Apply the settings.

Record the configured port because the connection command must use the same number.

Changing port 22 to another port can reduce automated connection attempts. Keep the security level set to High for current SSH clients. Account security, local-network restrictions, firewall rules, current encryption algorithms, and short service availability provide the meaningful protection.

Do not expose the SSH port directly to the internet through router port forwarding. For access away from home, first establish a trusted VPN connection to the local network. Our guide to securing UGREEN NAS and your home network covers the broader remote-access controls.

How to Connect to UGREEN NAS over SSH

The SSH command uses four values:

ssh -p PORT USERNAME@NAS_IP

Replace:

  • PORT with the SSH port configured in UGOS Pro
  • USERNAME with the administrator-account username
  • NAS_IP with the NAS IP address

For example:

ssh -p 22 adminname@192.168.1.50

Connect from Windows 10 or Windows 11

Open Windows Terminal or PowerShell and enter:

ssh -p PORT USERNAME@NAS_IP

For example:

ssh -p 22 adminname@192.168.1.50

On the first connection, OpenSSH displays a host-authenticity message and asks whether you want to continue. Check that the IP address belongs to your NAS and that you initiated the connection from the expected network before accepting the host key.

Enter:

yes

OpenSSH saves the host key and asks for the administrator password.

Nothing appears on screen while you type the password—not even dots or asterisks. This is normal Terminal behavior. Type the password carefully and press Enter.

If Windows reports that ssh is not recognized, search Windows Settings for Optional features, then install OpenSSH Client. Microsoft documents OpenSSH Client as an optional Windows feature and identifies ssh as its command-line client. Microsoft’s OpenSSH overview provides the current Windows availability details.

Connect from macOS or Linux

Open Terminal and enter the same command:

ssh -p PORT USERNAME@NAS_IP

For example:

ssh -p 22 adminname@192.168.1.50

Confirm the host key on the first connection, then enter the UGOS Pro administrator password. The password remains invisible while you type.

A successful login opens a shell under the administrator account. You have not obtained root privileges yet.

How to Get Root Access with sudo

After signing in with the administrator account, run:

sudo -i

Enter the same UGOS Pro administrator password again.

Verify the active account with:

whoami

The expected result is:

root

You now have a root shell. Limit this session to commands that genuinely require root privileges. A mistyped command can alter permissions, stop services, remove files, or make UGOS Pro unavailable.

When the privileged task is complete, leave the root shell:

exit

This returns you to the administrator shell. Run exit again to close the SSH connection:

exit

How to Set Up SSH Key Authentication

SSH keys let a trusted computer authenticate with a cryptographic key instead of sending the NAS account password for every connection.

Before configuring a key, enable the Personal Folder for the administrator account in UGOS Pro. OpenSSH stores the permitted public keys in that user’s home directory.

Keep an existing password-authenticated SSH session open while completing these steps. If the key configuration is wrong, the original session provides a way to correct it.

1. Generate an Ed25519 key

On Windows PowerShell, macOS, or Linux, run:

ssh-keygen -t ed25519

Press Enter to accept the default file location. For an interactive administrator key, add a passphrase when prompted.

The command creates two files:

  • id_ed25519 is the private key and must remain on the computer.
  • id_ed25519.pub is the public key that can be copied to the NAS.

Never upload or share the private key.

2. Display the public key

On Windows PowerShell:

Get-Content $env:USERPROFILE\.ssh\id_ed25519.pub

On macOS or Linux:

cat ~/.ssh/id_ed25519.pub

Copy the complete single line beginning with ssh-ed25519.

3. Prepare the administrator’s SSH directory

Connect to the NAS with the administrator password. Do this under the administrator account before running sudo -i.

Create the required directory and file:

mkdir -p ~/.ssh
touch ~/.ssh/authorized_keys

Apply restrictive permissions:

chmod go-w "$HOME"
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys

OpenSSH’s server can reject public-key authentication when the user’s home directory, .ssh directory, or authorized_keys file is writable by other users. The OpenSSH server manual documents this permission check.

4. Add the public key

Run:

cat >> ~/.ssh/authorized_keys

Paste the complete public-key line, press Enter, and then press Ctrl+D to finish.

Reapply the file permission:

chmod 600 ~/.ssh/authorized_keys

5. Test a second SSH session

Leave the original session open. Open a second Terminal window and connect normally:

ssh -p PORT USERNAME@NAS_IP

If the private key has a passphrase, enter that passphrase.

Test key authentication again after restarting the NAS and after major UGOS Pro updates. If the key is suddenly ignored, inspect the home-folder and .ssh permissions before generating a replacement key.

Avoid editing the system-wide SSH configuration to disable password authentication unless you have a tested recovery route. An incorrect server configuration can lock every administrator out of SSH.

How to Fix UGREEN NAS SSH Errors

Error Likely cause What to check
Connection refused SSH is disabled, the automatic timeout expired, or the command uses the wrong port Reopen Control Panel > Terminal, verify that SSH is enabled, and match the command to the configured port
Connection timed out Wrong IP address, different network segment, local-network restriction, or firewall block Check the NAS IP, confirm the computer is on an permitted network, and review the relevant firewall rule
Permission denied Incorrect username, password, account role, or SSH key Use a UGOS Pro administrator account and verify the authentication method
sudo -i fails The connected account does not have the required administrator privileges Check the account role in UGOS Pro and reconnect with an administrator account
REMOTE HOST IDENTIFICATION HAS CHANGED The NAS was reset, reinstalled, replaced, or assigned an IP previously used by another device Stop and verify the NAS identity before removing the saved host key
No matching cipher found The client only supports algorithms excluded by High security mode Update the SSH client; use Low security only as a temporary legacy-compatibility measure
SSH key is ignored Personal Folder is disabled or the home, .ssh, or authorized_keys permissions are too open Enable the Personal Folder and reapply the documented permissions
ssh is not recognized The computer does not have an SSH client available Install OpenSSH Client or use a Terminal application that includes an SSH client

For connection or authentication details, add -v to the command:

ssh -v -p PORT USERNAME@NAS_IP

Verbose mode shows which address, port, host key, cipher, and authentication methods the client is attempting. It does not reveal the account password.

If SSH works from one local device but fails from another, compare the devices’ IP addresses and network segments. A firewall or local-only rule may permit one source while blocking the other. Use our guide to configuring UGREEN NAS firewall rules when the permitted source range needs adjustment.

Handle an unexpected host-key warning carefully

A changed host key is normal after reinstalling UGOS Pro, replacing the NAS, or reassigning an old IP address. It can also indicate that the connection is reaching an unexpected device.

Verify the NAS identity and IP address before deleting the stored key. Do not clear the warning simply to make the connection proceed.

What to Do After the SSH Session

Once the administrative task is complete:

  1. Run exit to leave the root shell.
  2. Run exit again to close the SSH connection.
  3. Disable SSH in Control Panel > Terminal, or confirm that the automatic disable timer will close it.
  4. Remove any temporary firewall or remote-access allowance.
  5. Record the files, permissions, packages, or settings you changed.
  6. Confirm that storage, backup, file-sharing, and application services still work.
  7. Restart the NAS only when the completed change requires it.

SSH should be available for a defined administrative task, not left open indefinitely. A short, documented session is easier to secure and much easier to reverse if something goes wrong.

Frequently Asked Questions

Does UGREEN NAS have a default root password?

UGOS Pro’s documented SSH workflow does not use a separate default root password. Connect with a UGOS Pro administrator account, run sudo -i, and enter the same administrator password again.

Which account should I use for SSH?

Use a UGOS Pro account with administrator privileges for the procedure in this guide. Root elevation with sudo -i depends on the connected account having the required administrative rights.

Why does nothing appear when I type my SSH password?

OpenSSH does not display password characters, dots, or asterisks in the Terminal. Type the password normally and press Enter.

Does changing the SSH port make the NAS secure?

Changing the port can reduce automated scans against port 22, but it does not secure the account by itself. Use strong administrator credentials, SSH keys, High security mode, local-network restrictions, firewall rules, and automatic service disabling.

Quick Navigation
Top Picks for You
UGREEN NASync DH2300
UGREEN NASync DH2300

$204.99 $269.99

Learn More
$65 OFF
flag
Related Reads
How to Configure UGREEN NAS Firewall Rules
How to Configure UGREEN NAS Firewall Rules
23/06/2025
How to Protect Your UGREEN NAS from Ransomware
How to Protect Your UGREEN NAS from Ransomware
23/12/2024