Article

Home Router Security: Basic Setup in One Evening

Your router is the one door standing between every device in your home and the internet, yet it's usually set up once and then forgotten. A handful of steps done in a single evening will close the most common holes and make life much harder for anyone trying to get into your network.

Change the default admin password

Factory login and password combos like admin/admin are printed right in the manual, and ready-made lists of these combinations circulate freely online. CISA directly advises changing both the username and password used to log in to your router, since default credentials can be publicly available to anyone (CISA, Home Network Security).

  • Open your router's admin panel — usually at 192.168.0.1 or 192.168.1.1 in your browser.
  • Set a long admin password that you don't reuse anywhere else.
  • While you're at it, change the network name (SSID) if it reveals the device model — that tips off an attacker to a list of known vulnerabilities.

Turn on WPA3 or strong Wi-Fi encryption

The encryption type determines whether a neighbor or a random passer-by can read your wireless traffic. In your Wi-Fi security settings, choose WPA3, and if some of your devices don't support it, use mixed WPA2/WPA3 mode or at least WPA2 with AES encryption. Outdated WEP and legacy WPA should not be used at all.

According to the Wi-Fi Alliance, WPA3-Personal provides stronger protection against password guessing and has been mandatory for Wi-Fi CERTIFIED devices since 2020 (Wi-Fi Alliance, Security). Make the network password itself long: the NSA recommends a passphrase of at least 20 characters. For more on choosing encryption and building a strong password, see our guide to Wi-Fi security.

Keep your router's firmware up to date

Firmware is your router's operating system, and new vulnerabilities are found in it regularly. A device without recent updates is the first to be compromised, and it drags the rest of the network down with it. CISA calls regular firmware updates one of the most effective steps you can take, and the NSA advises enabling automatic updates wherever possible.

  • Turn on automatic firmware updates if your router supports it.
  • Manually check for a new version in the admin panel every month or two.
  • If the manufacturer stopped releasing updates years ago, consider replacing the device.

Turn off WPS and remote management

WPS (connecting via a button or PIN code) is convenient, but its eight-digit PIN can be brute-forced, opening the network to an outsider. Remote management lets you reach the router's panel from the internet — if it's enabled, that panel is visible from outside and becomes a target for automated attacks. CISA recommends turning off both settings.

  • Find the WPS setting and switch it off.
  • Disable remote management (as well as Telnet and SSH access from outside your network).
  • Only allow access to the admin panel from your local network.

Set up a separate network for guests and smart devices

A smart bulb, a cheap camera, or a robot vacuum often goes years without an update. The NSA recommends keeping your main Wi-Fi, a guest Wi-Fi, and an IoT network separate, so that a breach of one weak device doesn't open a path to the whole network (NSA, Best Practices for Keeping Your Home Network Secure).

  • Turn on a guest network and connect visitors' devices and all smart gadgets to it.
  • Keep your main Wi-Fi for the computers and phones that hold your personal data.
  • If your router supports it, block guest-network devices from seeing each other (client isolation).

What else is worth closing off

A router protects the network inside your home, but your traffic beyond it is still visible to your ISP and to the owner of the access point at a café or hotel. Encrypting your traffic with an app like HamikVPN adds a separate layer of protection for the connection itself, especially on networks you don't control. For more on how this works at the connection level, see our article on encryption basics, and for phones and tablets there's a separate Android security checklist. You can get through all of these steps in a single evening, and after that keeping your router in shape only takes a check every couple of months.

Encrypt your traffic on any network
HamikVPN protects your connection and data at home and on public Wi-Fi.
Try it free

Frequently asked questions

Do I have to enable WPA3 if my old devices don't support it?
If some of your devices don't work with WPA3, choose mixed WPA2/WPA3 mode, or at least WPA2 with AES encryption. Avoid WEP and legacy WPA — they've been insecure for years.
How often should I update my router's firmware?
Turn on automatic updates, and manually check for a new version every month or two. If the manufacturer has abandoned your model, it may be time to replace the device.
How is a guest network different from the main one?
A guest network is isolated from your main network: devices on it can't see the computers and phones holding your personal data. It's a convenient place for guests' devices and smart gadgets.
What is WPS, and why is it recommended to disable it?
WPS is a simplified way to join Wi-Fi using a button or PIN code. Its eight-digit PIN can be brute-forced, so leaving WPS enabled weakens your network's security.
Is router configuration enough to protect my traffic?
A router protects the network inside your home, but on public Wi-Fi your traffic is visible to the access point's owner. Encrypting your connection with a VPN adds a separate layer of protection, especially on networks you don't control.