What this protects, and what it doesn't
Protects
- Against neighbours or passers-by joining your Wi-Fi and seeing or misusing your connection.
- Against attackers who take over routers that still use the default admin password or old firmware.
- Against a compromised smart device (camera, speaker, TV) reaching your laptops and phones.
- Against devices on your network opening ports to the internet without your knowledge.
Does not protect
- It does not hide your browsing from your internet provider. See the VPN or Tor guide for that.
- It does not secure the devices themselves: phones and laptops still need updates, and apps still collect data.
- A router that no longer receives firmware updates cannot be made safe with settings. Replace it.
- It does not protect you on other networks, such as hotel or café Wi-Fi.
Prerequisites
- The router's admin address and login. They are usually on a label on the router or in its manual, or in your internet provider's support pages.
- A password manager to store the new admin and Wi-Fi passwords.
- If your provider manages the router for you, its support page for router settings: some settings may only be changed by the provider.
Step by step
-
Change the router admin password
The admin password controls every setting on the router. The default one is often printed on the label or shared by every router of the same model.
- Open the router's admin page in a browser. BSI advises using the HTTPS address if the router offers one, and not browsing other sites while you change settings.
- Change the admin username (if possible) and password. CISA recommends a password that is long, random and unique, and not reused anywhere else. The password generator can create one.
- Save it in your password manager.
-
Update the firmware, and turn on automatic updates
Router firmware updates fix known vulnerabilities. Check the router's admin page for an update function and turn on automatic updates if it exists. Both CISA and BSI recommend this.
Check how long the manufacturer supports the model. A router that no longer gets updates should be replaced, even if it still works.
-
Use WPA3 or WPA2 (AES) with a strong passphrase
- In the Wi-Fi security settings, choose WPA3 Personal. If some of your devices cannot connect, use the WPA2/WPA3 mixed mode, or WPA2 with AES.
- Do not use an open network, WEP, WPA or WPA2 with TKIP: CISA calls these unsafe. If your router offers nothing better, ask your provider for a new one or replace it.
- Set a Wi-Fi passphrase of several unrelated words. CISA suggests 5 to 7 unrelated words, at least 16 characters, not used anywhere else.
-
Rename the network without personal details
Change the default network name (SSID). CISA advises against including sensitive or identifying information, such as your name, flat number or the router model. BSI also recommends removing anything that reveals the router's model or firmware version where you can.
-
Put visitors and smart devices on a guest network
Turn on the router's guest network with its own strong passphrase. Give that one to visitors. CISA also suggests connecting smart home devices (TV, speakers, cameras, appliances) to the guest network when they only need internet access, so that a compromised device cannot reach your computers and phones.
Some smart devices need to be on the same network as the phone that controls them. In that case, keep their number low and their firmware updated.
-
Turn off WPS, UPnP and remote management
- WPS (Wi-Fi Protected Setup, the button or PIN pairing): CISA says it increases the chance that someone gets onto your Wi-Fi without permission. Turn it off.
- UPnP lets devices on your network open ports to the internet by themselves. CISA warns that attackers can abuse it to spread malware and control devices remotely. Turn it off; if a device needs it to be added, switch it on only for that and off again.
- Remote management (administration from the internet): turn it off unless you really need it. Then the router can only be changed from inside your home network.
Leave the router's firewall on. BSI advises not changing firewall rules unless you understand what each open port does. The port lookup explains common port numbers.
-
Check what is connected
Most routers list connected devices. Go through the list and make sure you recognise each one. An unknown entry may only show a hardware (MAC) address: the MAC address lookup tells you the manufacturer, which often identifies it. Many phones use a random MAC address per network, so the manufacturer may show as unknown.
If you find a device you cannot explain, change the Wi-Fi passphrase. Every device then has to reconnect with the new one.
-
Secure each smart device
The UK NCSC advises, for every smart device: change any default password, turn on two-step verification if the app offers it, turn on automatic updates, review the default settings, and turn off remote access you do not need. Before selling or giving a device away, factory reset it.
-
Encrypt DNS on your devices
DNS lookups, which turn site names into addresses, are often sent unencrypted to your provider. Changing the DNS server on the router alone does not encrypt them. Turn on encrypted DNS in each browser or operating system: see Encrypt your DNS lookups.
-
Keep the router where visitors cannot reach it
Anyone with physical access can factory reset the router and log in with the default details on its label. CISA advises keeping it in a secure place.
Your ticks are saved in this browser only (see or delete local data).
Common mistakes
- Keeping the default admin password because the Wi-Fi password was changed.
- Leaving WPS on because the pairing button is convenient.
- Turning UPnP on for one game console and never turning it off again.
- Putting smart cameras and speakers on the same network as work laptops.
- Keeping a router that has not had a firmware update in years.
- Using your name or address as the network name.
Going further
Your internet provider still sees which sites you connect to. If that matters for your threat model, read VPN or Tor: which one, and when. To see what each site can still learn about your browser, try the Browser Fingerprint Inspector.