NETWORK

A router out of the box — seven settings to review

Factory router settings are a starting point, not complete protection. Review updates, admin access, Wi-Fi, WPS, guests, IoT, and internet-facing access.

Tomek7 min readBEGINNER

A new router will usually bring the internet up and enable Wi-Fi encryption. That does not mean its configuration is finished. Vendor defaults have to work in many homes; they do not decide which devices and services your home needs.

1. Model and updates

Record the exact model and hardware revision from the label. In the admin panel, check the firmware version and the date of its last update. If the router can update automatically, enable that feature. If it cannot, download firmware only from the vendor page for that exact variant.

Changing one setting cannot make an unsupported router safe. If the vendor has ended security support, plan to replace it.

2. Administrator password

The router panel needs its own long password, different from the Wi-Fi password. Replace the factory credentials. If the vendor uses a cloud account, protect that account with an extra login factor when available.

3. WPA2 or WPA3

Choose WPA3 if all important devices support it. Mixed WPA2/WPA3 mode is a reasonable compromise for older equipment. Do not use WEP or the old WPA. The Wi-Fi password should be long and not reused on other services.

Hiding the network name and filtering MAC addresses do not replace encryption. A hidden network name can still be discovered, and an allowed MAC address can be copied or spoofed.

4. WPS

WPS makes connection easier through a button or PIN, but it is usually unnecessary after setup. Turn it off if you do not use it. If you need WPS, prefer the push button over a fixed PIN and disable the feature after adding the device.

5. Guests and IoT devices

A guest network should provide internet access without access to home devices. Check that local-network access is disabled. Cameras, TVs, and inexpensive IoT devices are worth separating when the router allows it — but a “Guest” label does not prove isolation. Test the behaviour, not only the name.

This is a small version of network segmentation: a device receives only the access it needs.

6. Internet management and exposed services

Disable administration of the router from the internet unless you knowingly use it. Review port forwards, the DMZ host, and UPnP. UPnP is convenient, but it lets applications add forwards; disable it when unnecessary, then check games, calls, and devices that depended on it.

An empty list in the panel does not prove that the provider exposes no other feature. One open port does not prove a compromise either — the address, service, and context matter.

7. DNS and logs without guesswork

Do not change DNS only because someone called one address “secure”. Record who operates the resolver, why you chose it, and whether devices actually use it. Encrypted DNS may reduce who can read queries in transit, but it does not automatically filter malicious sites or hide all traffic.

A router log can help establish the time of a restart, an address lease, or a login attempt if the device records those events. No entry is not proof that nothing happened; home routers have limited storage and different logging levels.

After the changes, save a configuration backup with no passwords in its filename and keep it outside the router. The export may contain Wi-Fi passwords, VPN keys, or other secrets, so treat it as confidential and store it encrypted or with restricted access. If the internet disappears after a change, follow the network troubleshooting cheat sheet in order instead of disabling every protection. The 15-minute home network review covers the whole check.

Want this in a lab or in production?

The article stays free. The form is for scope, not a paywall.

The inquiry is stored on the server. You will get a short confirmation from hello@tomek.st. The operator is also notified on Telegram and email.