Home AI Threats Free Help Services About IT Support Contact Book Consultation →
Back to Free Help
25 minutes10 steps

How to Lock Down Your Home Router

Your home router is the front door to your entire digital life. Every device in your house connects through it. Most routers ship with terrible default settings that attackers actively scan for. This guide walks you through locking it down properly.

1

Change default admin credentials

Open your browser and type your router's IP address — usually 192.168.1.1 or 192.168.0.1. Log in with the default credentials (check the sticker on the bottom of your router). Go to Administration settings and change both the admin username and password to something strong and unique — at least 16 characters, stored in your password manager.

Tip: If you can't find your router's IP, open a command prompt and type ipconfig (Windows) or check network settings on Mac — look for "Default Gateway."
2

Disable remote management

Find "Remote Management," "Remote Access," or "Web Access from WAN" in your admin panel and turn it off. This prevents anyone outside your home network from accessing your router's admin panel. Also disable "cloud management" unless you specifically need it.

Warning: If left on, anyone who discovers your router's public IP can attempt to log in. Automated bots scan for this constantly.
3

Enable WPA3 encryption (or WPA2-AES)

In wireless security settings, set encryption to WPA3-Personal if supported, otherwise WPA2-AES. Never use WEP or WPA-TKIP — these are broken and can be cracked in minutes. Set a strong Wi-Fi password different from your admin password.

4

Create a guest network for IoT devices

Set up a separate guest network and connect all smart devices to it — TVs, plugs, vacuums, voice assistants. This isolates them so if one gets compromised, the attacker can't pivot to your main devices where sensitive data lives.

5

Schedule firmware update checks

Look for "Firmware Update" in your admin panel. Enable automatic updates if available. If not, set a phone reminder to check every 30 days. Download firmware only from your manufacturer's official website.

6

Disable UPnP (Universal Plug and Play)

UPnP allows devices to automatically open ports without your knowledge — a well-known attack vector. Find it under Advanced or NAT settings and turn it off. If an app stops working, manually forward just the ports it needs.

7

Enable the router firewall

Navigate to Security or Firewall settings and make sure it's on. Enable SPI (Stateful Packet Inspection) if available. This inspects incoming traffic and blocks suspicious connections before they reach your devices.

8

Disable WPS (Wi-Fi Protected Setup)

The WPS PIN method has a known vulnerability allowing brute-force attacks in hours. Disable WPS completely in wireless settings. You can always connect devices by typing your Wi-Fi password manually.

9

Set up DHCP reservations for trusted devices

Assign fixed IP addresses to your known devices based on their MAC address. This makes it easier to spot unfamiliar devices on your network. Any new device will get an IP outside your reserved range, making it immediately visible.

10

Limit DHCP pool size for guest network

Limit the guest/IoT network's DHCP range to just above the number of devices you own. If you have 8 smart devices, set the pool to 10. This limits how many devices can connect and makes unauthorized connections easier to detect.

Need help configuring your router?

Every router's admin panel looks different. If you'd like personalized, step-by-step assistance walking through your specific router model, we're here to help.

Contact Us