Home Network Hardening
14 items · Technical · Medium difficulty · 45 min
Practical steps to lock down your home Wi‑Fi and router.
-
Update router firmware
Use the router UI or manufacturer's site; back up settings before applying updates.
-
Change default admin username and password
Create a unique username and long password; store it in a password manager.
-
Disable remote administration / WAN management
Turn off web/SSH access from the internet to the router interface.
-
Enable router firewall and intrusion protection features
Activate built-in firewall, SPI, and any IDS/IPS options available.
-
Enable WPA3 or strongest available Wi‑Fi encryption
Choose WPA3; if devices don't support it, use WPA2‑AES (not TKIP).
-
Set a strong, unique Wi‑Fi SSID and passphrase
Avoid personal info in the SSID; use a long passphrase for the network.
-
Create an isolated guest network for IoT and visitors
Enable guest SSID and disable access to your main LAN devices (AP/guest isolation).
-
Disable WPS (Wi‑Fi Protected Setup)
Turn off WPS to prevent PIN-based brute-force attacks.
-
Disable UPnP on the router
Turn off UPnP unless absolutely needed; it can expose devices to the internet.
-
Review DHCP leases and connected devices
Open the router's client list and identify each connected device.
-
Limit DHCP range to needed addresses
Shrink the DHCP pool to match only the number of devices you use.
-
Remove unknown devices and reserve MACs for trusted devices
Disconnect unrecognized devices and set static reservations for trusted hardware.
-
Enable encrypted DNS (DNS‑over‑HTTPS or DNS‑over‑TLS)
Set DoH/DoT on the router or devices; use providers like 1.1.1.1 or 9.9.9.9.
-
Consider router‑level VPN or use VPN on key devices
Install a VPN client on the router or run VPN apps on PCs/phones for extra privacy.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.