How to Enable SSH and Get Root Access on UGREEN NAS
You can enable SSH from Control Panel > Terminal in UGOS Pro and connect from Windows, macOS, or Linux. Sign in through SSH with a UGOS Pro administrator account, then run sudo -i when you need root privileges.
Because a root shell can change or delete system files, restrict SSH to trusted devices, keep the security level set to High, and disable the service when you finish.

Before You Enable SSH on UGREEN NAS
Prepare the following before opening a Terminal session:
- The username and password of a UGOS Pro administrator account
- The local IP address of the NAS
- A computer connected to the same trusted network
- Continued access to the UGOS Pro web interface
- A clear record of the command or configuration you intend to change
Create an independent copy of important files before making system-level changes. Our guide to choosing a NAS backup strategy explains how to separate RAID availability, local backup, and off-site recovery.
SSH access itself is an administrative feature. Changes to system files, permissions, services, or package dependencies can affect UGOS Pro stability, security, and future updates.
How to Enable SSH in UGOS Pro
- Sign in to UGOS Pro with an administrator account.
- Open Control Panel.
- Select Terminal.
- Enable SSH.
- Keep the default port or enter a custom port number.
- Set an automatic disable time so the service does not remain available longer than necessary.
- Open the advanced SSH settings.
- Keep the security level set to High.
- Restrict the permitted access range to the local network when possible.
- Enable SFTP only if you need to transfer files through the SSH service.
- Apply the settings.
Record the configured port because the connection command must use the same number.
Changing port 22 to another port can reduce automated connection attempts. Keep the security level set to High for current SSH clients. Account security, local-network restrictions, firewall rules, current encryption algorithms, and short service availability provide the meaningful protection.
Do not expose the SSH port directly to the internet through router port forwarding. For access away from home, first establish a trusted VPN connection to the local network. Our guide to securing UGREEN NAS and your home network covers the broader remote-access controls.
How to Connect to UGREEN NAS over SSH
The SSH command uses four values:
ssh -p PORT USERNAME@NAS_IP
Replace:
-
PORTwith the SSH port configured in UGOS Pro -
USERNAMEwith the administrator-account username -
NAS_IPwith the NAS IP address
For example:
ssh -p 22 adminname@192.168.1.50
Connect from Windows 10 or Windows 11
Open Windows Terminal or PowerShell and enter:
ssh -p PORT USERNAME@NAS_IP
For example:
ssh -p 22 adminname@192.168.1.50
On the first connection, OpenSSH displays a host-authenticity message and asks whether you want to continue. Check that the IP address belongs to your NAS and that you initiated the connection from the expected network before accepting the host key.
Enter:
yes
OpenSSH saves the host key and asks for the administrator password.
Nothing appears on screen while you type the password—not even dots or asterisks. This is normal Terminal behavior. Type the password carefully and press Enter.
If Windows reports that ssh is not recognized, search Windows Settings for Optional features, then install OpenSSH Client. Microsoft documents OpenSSH Client as an optional Windows feature and identifies ssh as its command-line client. Microsoft’s OpenSSH overview provides the current Windows availability details.
Connect from macOS or Linux
Open Terminal and enter the same command:
ssh -p PORT USERNAME@NAS_IP
For example:
ssh -p 22 adminname@192.168.1.50
Confirm the host key on the first connection, then enter the UGOS Pro administrator password. The password remains invisible while you type.
A successful login opens a shell under the administrator account. You have not obtained root privileges yet.
How to Get Root Access with sudo
After signing in with the administrator account, run:
sudo -i
Enter the same UGOS Pro administrator password again.
Verify the active account with:
whoami
The expected result is:
root
You now have a root shell. Limit this session to commands that genuinely require root privileges. A mistyped command can alter permissions, stop services, remove files, or make UGOS Pro unavailable.
When the privileged task is complete, leave the root shell:
exit
This returns you to the administrator shell. Run exit again to close the SSH connection:
exit
How to Set Up SSH Key Authentication
SSH keys let a trusted computer authenticate with a cryptographic key instead of sending the NAS account password for every connection.
Before configuring a key, enable the Personal Folder for the administrator account in UGOS Pro. OpenSSH stores the permitted public keys in that user’s home directory.
Keep an existing password-authenticated SSH session open while completing these steps. If the key configuration is wrong, the original session provides a way to correct it.
1. Generate an Ed25519 key
On Windows PowerShell, macOS, or Linux, run:
ssh-keygen -t ed25519
Press Enter to accept the default file location. For an interactive administrator key, add a passphrase when prompted.
The command creates two files:
-
id_ed25519is the private key and must remain on the computer. -
id_ed25519.pubis the public key that can be copied to the NAS.
Never upload or share the private key.
2. Display the public key
On Windows PowerShell:
Get-Content $env:USERPROFILE\.ssh\id_ed25519.pub
On macOS or Linux:
cat ~/.ssh/id_ed25519.pub
Copy the complete single line beginning with ssh-ed25519.
3. Prepare the administrator’s SSH directory
Connect to the NAS with the administrator password. Do this under the administrator account before running sudo -i.
Create the required directory and file:
mkdir -p ~/.ssh
touch ~/.ssh/authorized_keys
Apply restrictive permissions:
chmod go-w "$HOME"
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
OpenSSH’s server can reject public-key authentication when the user’s home directory,
.sshdirectory, orauthorized_keysfile is writable by other users. The OpenSSH server manual documents this permission check.
4. Add the public key
Run:
cat >> ~/.ssh/authorized_keys
Paste the complete public-key line, press Enter, and then press Ctrl+D to finish.
Reapply the file permission:
chmod 600 ~/.ssh/authorized_keys
5. Test a second SSH session
Leave the original session open. Open a second Terminal window and connect normally:
ssh -p PORT USERNAME@NAS_IP
If the private key has a passphrase, enter that passphrase.
Test key authentication again after restarting the NAS and after major UGOS Pro updates. If the key is suddenly ignored, inspect the home-folder and .ssh permissions before generating a replacement key.
Avoid editing the system-wide SSH configuration to disable password authentication unless you have a tested recovery route. An incorrect server configuration can lock every administrator out of SSH.
How to Fix UGREEN NAS SSH Errors
| Error | Likely cause | What to check |
|---|---|---|
Connection refused |
SSH is disabled, the automatic timeout expired, or the command uses the wrong port | Reopen Control Panel > Terminal, verify that SSH is enabled, and match the command to the configured port |
Connection timed out |
Wrong IP address, different network segment, local-network restriction, or firewall block | Check the NAS IP, confirm the computer is on an permitted network, and review the relevant firewall rule |
Permission denied |
Incorrect username, password, account role, or SSH key | Use a UGOS Pro administrator account and verify the authentication method |
sudo -i fails |
The connected account does not have the required administrator privileges | Check the account role in UGOS Pro and reconnect with an administrator account |
REMOTE HOST IDENTIFICATION HAS CHANGED |
The NAS was reset, reinstalled, replaced, or assigned an IP previously used by another device | Stop and verify the NAS identity before removing the saved host key |
No matching cipher found |
The client only supports algorithms excluded by High security mode | Update the SSH client; use Low security only as a temporary legacy-compatibility measure |
| SSH key is ignored | Personal Folder is disabled or the home, .ssh, or authorized_keys permissions are too open |
Enable the Personal Folder and reapply the documented permissions |
ssh is not recognized |
The computer does not have an SSH client available | Install OpenSSH Client or use a Terminal application that includes an SSH client |
For connection or authentication details, add -v to the command:
ssh -v -p PORT USERNAME@NAS_IP
Verbose mode shows which address, port, host key, cipher, and authentication methods the client is attempting. It does not reveal the account password.
If SSH works from one local device but fails from another, compare the devices’ IP addresses and network segments. A firewall or local-only rule may permit one source while blocking the other. Use our guide to configuring UGREEN NAS firewall rules when the permitted source range needs adjustment.
Handle an unexpected host-key warning carefully
A changed host key is normal after reinstalling UGOS Pro, replacing the NAS, or reassigning an old IP address. It can also indicate that the connection is reaching an unexpected device.
Verify the NAS identity and IP address before deleting the stored key. Do not clear the warning simply to make the connection proceed.
What to Do After the SSH Session
Once the administrative task is complete:
- Run
exitto leave the root shell. - Run
exitagain to close the SSH connection. - Disable SSH in
Control Panel > Terminal, or confirm that the automatic disable timer will close it. - Remove any temporary firewall or remote-access allowance.
- Record the files, permissions, packages, or settings you changed.
- Confirm that storage, backup, file-sharing, and application services still work.
- Restart the NAS only when the completed change requires it.
SSH should be available for a defined administrative task, not left open indefinitely. A short, documented session is easier to secure and much easier to reverse if something goes wrong.

Frequently Asked Questions
Does UGREEN NAS have a default root password?
UGOS Pro’s documented SSH workflow does not use a separate default root password. Connect with a UGOS Pro administrator account, run sudo -i, and enter the same administrator password again.
Which account should I use for SSH?
Use a UGOS Pro account with administrator privileges for the procedure in this guide. Root elevation with sudo -i depends on the connected account having the required administrative rights.
Why does nothing appear when I type my SSH password?
OpenSSH does not display password characters, dots, or asterisks in the Terminal. Type the password normally and press Enter.
Does changing the SSH port make the NAS secure?
Changing the port can reduce automated scans against port 22, but it does not secure the account by itself. Use strong administrator credentials, SSH keys, High security mode, local-network restrictions, firewall rules, and automatic service disabling.