Josh DargieInfrastructure · Cloud · Software

Blog / how-to

How to Back Up and Restore a UniFi Controller

How to set up UniFi cloud and local backups properly, what the backup actually contains, and how to restore one when the hardware dies.

By the end of this one you will have automatic cloud backups of your UniFi setup running, a local copy stored somewhere that isn't the gateway itself, and you will know exactly what to click when the hardware dies. This is for anyone running a UniFi Cloud Gateway, Dream Machine, or Cloud Key, whether at home or in a small business.

I will say this up front: the backup is the part of a UniFi install almost nobody checks until the day they need it. The configuration on a decent network (VLANs, firewall rules, Wi-Fi networks, camera settings) represents hours of work. Losing it means rebuilding from memory, and memory is worse than you think.

One caveat before the steps. Ubiquiti moves menus between releases, so treat the paths here as a starting point and the concepts as the actual instructions. If a setting isn't where I say it is, it moved, it didn't disappear.

Know which kind of backup you're dealing with

UniFi has two backup types and people mix them up constantly.

A system config backup covers a Cloud Gateway or Cloud Key: the OS settings, every installed application (Network, Protect, Talk, Access), and the device configurations. This is the one you want for a full recovery.

A network-only backup is a .unf file containing just the Network application's settings and device configs. It's the right tool if you self-host the Network Server on a PC, or if you're moving Network settings between installations, but it does not carry your Protect or Talk configuration.

If you have a UniFi console (any Dream Machine, Gateway, or Cloud Key), work with system config backups and keep the .unf in your back pocket for migrations.

Turn on automatic cloud backups

This is the single most important step, and it takes two minutes.

Your console needs to be linked to a UI account. If you skipped that during setup, do it now, because cloud backups save to the account, not the device. With that in place, enabled cloud backups generate automatically every week and before each major update, and you can see them by logging in at account.ui.com/backups.

Two gotchas here, and both come from real patterns I see on takeover jobs. First, only the console's Owner account can manage these backups. If the owner is a personal email belonging to someone who left the company, or to the installer you no longer talk to, your backups are effectively hostage. Sort out ownership before you need a restore, not during one. Second, "I'm sure it was enabled" is not the same as seeing dated backup files sitting in the account. Look.

Download a local copy too

Cloud backups are good. They are not sufficient on their own, because they assume your UI account is accessible and the cloud service is reachable on the worst day of your year.

Go to Settings > Control Plane > Backups and download a backup file. Put it somewhere that is not the console: a NAS, a proper backup drive, wherever your other important files live. A backup stored only on the device it's protecting is a note to your future self, not a backup. I'd repeat the download after any significant configuration change, like a VLAN redesign or a new set of firewall rules.

Understand what's not in there

The backup contains configuration, not data. The one that catches people: Protect camera recordings are not in the backup and cannot move between consoles. If the console dies, the footage on it is gone unless the drives survive and stay in the original hardware. If retention matters to you (insurance, incidents, compliance), plan for it separately rather than assuming the backup has you covered.

Restoring when the day comes

On a working console, restore from Settings > Control Plane > Backups, choose Restore, and pick either the most recent cloud backup or upload your local file. By default "Restore All Applications and Settings" is on; you can untick it to restore selectively, which is handy when only one application's config went sideways.

On a replacement console, you can restore when the setup wizard offers it, or complete setup and restore from the same menu afterward. If you're moving to a different model of gateway, the new device needs UniFi OS 3.1 or newer for the migration to work. Adopted devices generally come back with the config; give the system time to push settings out before you start troubleshooting things that would have fixed themselves.

Test it

Don't trust, verify. Log in at account.ui.com/backups and confirm dated backups exist. Confirm the Owner account is one your business actually controls. Download a local copy and check the file isn't zero bytes. That's a fifteen-minute audit, and it's the difference between a bad morning and a bad month.

Where this gets harder than a blog post

The backup itself is a one-time setup and I've just given you the whole thing. What it doesn't replace is the ongoing part: someone watching firmware releases, checking that backups keep landing, and catching problems before the restore is needed. That's a service, not a Saturday job. And migrations between console models, self-hosted servers, or anything multi-site have enough sharp edges that a second set of eyes is cheap insurance. If you'd like mine on your setup, that's exactly what I do.

Sources

← All posts

Start with a conversation

Thirty minutes, no charge, no pitch.

Tell me the problem. I'll tell you whether I'm the right person for it, and if not, who is.