Your home router is the front door to your entire digital life. Every device in your house connects through it. Most routers ship with terrible default settings that attackers actively scan for. This guide walks you through locking it down properly.
Open your browser and type your router's IP address — usually 192.168.1.1 or 192.168.0.1. Log in with the default credentials (check the sticker on the bottom of your router). Go to Administration settings and change both the admin username and password to something strong and unique — at least 16 characters, stored in your password manager.
Find "Remote Management," "Remote Access," or "Web Access from WAN" in your admin panel and turn it off. This prevents anyone outside your home network from accessing your router's admin panel. Also disable "cloud management" unless you specifically need it.
In wireless security settings, set encryption to WPA3-Personal if supported, otherwise WPA2-AES. Never use WEP or WPA-TKIP — these are broken and can be cracked in minutes. Set a strong Wi-Fi password different from your admin password.
Set up a separate guest network and connect all smart devices to it — TVs, plugs, vacuums, voice assistants. This isolates them so if one gets compromised, the attacker can't pivot to your main devices where sensitive data lives.
Look for "Firmware Update" in your admin panel. Enable automatic updates if available. If not, set a phone reminder to check every 30 days. Download firmware only from your manufacturer's official website.
UPnP allows devices to automatically open ports without your knowledge — a well-known attack vector. Find it under Advanced or NAT settings and turn it off. If an app stops working, manually forward just the ports it needs.
Navigate to Security or Firewall settings and make sure it's on. Enable SPI (Stateful Packet Inspection) if available. This inspects incoming traffic and blocks suspicious connections before they reach your devices.
The WPS PIN method has a known vulnerability allowing brute-force attacks in hours. Disable WPS completely in wireless settings. You can always connect devices by typing your Wi-Fi password manually.
Assign fixed IP addresses to your known devices based on their MAC address. This makes it easier to spot unfamiliar devices on your network. Any new device will get an IP outside your reserved range, making it immediately visible.
Limit the guest/IoT network's DHCP range to just above the number of devices you own. If you have 8 smart devices, set the pool to 10. This limits how many devices can connect and makes unauthorized connections easier to detect.
Every router's admin panel looks different. If you'd like personalized, step-by-step assistance walking through your specific router model, we're here to help.