How-To Guides

How to Secure Your Home Router

Your router is the gateway to every device in your home. Default settings are often insecure. This guide hardens your router and Wi-Fi in seven practical steps.

Why Router Security?

Your router sits between every phone, laptop, smart bulb, and baby monitor in your home and the public internet. If an attacker compromises it, they can monitor your traffic, redirect your banking visits to lookalike sites, hijack your DNS, and use your devices as part of a botnet without you ever noticing.

Default router settings are designed for ease of use -- not security. Many ship with default admin passwords printed on a sticker, weak Wi-Fi encryption, and features like WPS and remote management switched on by default. Each of these is a door an attacker can walk through.

Spending 30 minutes hardening your router is one of the highest-value security moves you can make. Let us walk through it step by step.

Step 1. Change the Default Admin Password

The very first thing every router owner should do is change the administrator password. Default admin credentials are published online for every consumer router model -- attackers can find them in seconds.

  1. 1.Connect to your network and open a web browser.
  2. 2.Navigate to your router's admin page, usually at 192.168.0.1 or 192.168.1.1. If neither works, check your router sticker or manual.
  3. 3.Find the default admin username and password printed on the router's bottom sticker. Log in with these defaults.
  4. 4.Navigate to the Administration or Security section and locate "Change admin password" or "Account password".
  5. 5.Set a long, unique password -- at least 16 characters. Generate one with a password manager and store it there.
  6. 6.Save, log out, and immediately log back in with the new password to confirm everything works.

Note: This is the admin password for the router itself, separate from your Wi-Fi password. You need both, and they should be different.

Step 2. Update Firmware

Router vendors release firmware patches to fix security vulnerabilities. Many routers never get patched because users ignore this menu. Take ten minutes to update and turn on auto-update if available.

  1. 1.In the admin panel, look for a section called Firmware Update, System Update, or Router Update. The exact name varies by brand.
  2. 2.Click Check for updates and let the router fetch the latest signed firmware from the vendor.
  3. 3.If an update is available, install it. The router will reboot -- expect 2-5 minutes of downtime.
  4. 4.Look for an option to Enable automatic firmware updates. Turn it on if present.
  5. 5.Recheck monthly for updates even with auto-update enabled, since some vendors require manual approval for major releases.

Step 3. Lock Down Wi-Fi Security

Wi-Fi encryption is the only thing stopping neighbors and passers-by from joining your network and reading your traffic. Set it to the strongest available mode.

  1. 1.Open the Wireless or Wi-Fi settings section in your admin panel.
  2. 2.If your router supports WPA3, select WPA3-Personal. WPA3 is the current standard and resists brute force much better than WPA2.
  3. 3.If your router or any of your devices do not yet support WPA3, choose WPA2-AES (sometimes labeled WPA2-PSK with AES). This is still reasonably secure.
  4. 4.Never use WEP. WEP can be cracked by a script kiddie in under a minute. If WEP is your only option, your router is too old -- replace it.
  5. 5.Change your Wi-Fi password (the network passphrase, separate from the admin password) to at least 15 characters, mixing words and symbols. A passphrase like purple-panda-river-coffee is more secure and easier to share than a short mess.
  6. 6.Avoid "Mixed WPA2/WPA3" mode if possible -- downgrade attacks can force clients onto the weaker WPA2. Prefer pure WPA3 or pure WPA2.

Step 4. Disable WPS

Wi-Fi Protected Setup (WPS) was designed to make connecting devices easier by entering an 8-digit PIN instead of a long passphrase. The protocol is mathematically broken -- the PIN can be brute-forced in hours.

  1. 1.Open your router admin panel.
  2. 2.Navigate to the Wireless settings or WPS page.
  3. 3.Locate the WPS toggle and set it to Off or Disabled.
  4. 4.If your router has a physical WPS button, do not press it for pairing. New devices can join by typing your 15+ character passphrase -- it takes a few extra seconds and is far safer.

Step 5. Set Up a Guest Network

Visitors and IoT devices (smart bulbs, smart speakers, robot vacuums, baby monitors) should not share your main network. They are harder to patch and more likely to be compromised. A guest network isolates them from your laptop, phone, and NAS.

  1. 1.In the Wireless settings, look for a Guest Network option.
  2. 2.Turn it on. Set a different SSID (network name) like YourHome-Guest.
  3. 3.Set a strong passphrase separate from your main network.
  4. 4.Enable Client Isolation or Prevent guests from seeing each other if available. This prevents guests from scanning each other's devices.
  5. 5.Connect all IoT devices to this guest network. Save your main network for devices you trust: laptops, phones, your primary desktop.

Step 6. Disable Remote Management

Many routers expose their admin interface to the public internet by default. That means anyone, anywhere, can attempt to log into your router's admin page. Unless you specifically need remote admin access (most people do not), disable it.

  1. 1.Open the Administration or Remote Management section in your admin panel.
  2. 2.Find Remote Management, Remote Admin, or Web Access from WAN.
  3. 3.Set it to Disabled.
  4. 4.If you genuinely need remote access, set up a VPN to your home network instead. VPNs provide authenticated, encrypted tunnel access without exposing the raw admin page.

Step 7. Change Your DNS Provider

DNS is the phonebook of the internet. Your ISP-provided default DNS is slow, often logs your browsing, and does nothing to block malicious sites. Switching takes two minutes and improves privacy and performance.

  • •Cloudflare 1.1.1.1. Free, fast, privacy-respecting. Set primary to 1.1.1.1 and secondary to 1.0.0.1.
  • •Pi-hole. Run it on a Raspberry Pi (or any always-on Linux box) to block ads and trackers network-wide. Devices do not need per-app ad blockers.
  • •NextDNS. A cloud Pi-hole-equivalent that blocks malware and trackers at DNS, with family filter options.

On your router, look for a DNS or Internet Setup section, replace the ISP's default DNS with your chosen provider's addresses, and save. Every device on your network benefits immediately.

Quick Tips

  • •Hiding your SSID offers only minor security benefit -- attackers can still detect the network -- but it does reduce casual interest.
  • •Disable UPnP unless a specific app requires it. UPnP automatically opens ports and is a frequent source of accidental exposures.
  • •Check the list of connected devices regularly -- in the admin panel's "Attached Devices" or "DHCP clients" section. Anything you do not recognize is worth investigating.
  • •Consider replacing your router if it is more than 5 years old. Vendors stop releasing security patches and the device becomes a permanent vulnerability.
  • •Write your admin password and Wi-Fi password on a slip of paper kept in a secure location -- useful when guests need access or you reset a device.

Visual Walkthrough

Slide 1
1 / 13

Need More Help?

Router admin panels vary wildly by brand and model. If your router's interface does not match this guide, or you want help auditing your network the right way, book a free StarCaller Academy call -- we will walk you through it live.