Affiliate Disclosure: This article may contain affiliate links. If you purchase through these links, we may earn a commission at no extra cost to you.
Every device in your home — laptops, phones, security cameras, smart plugs — connects through one box: your router. If that box still runs its factory admin password and an outdated encryption standard, anyone within range can borrow your bandwidth, watch unencrypted traffic, or probe the devices behind it. Router makers like ASUS, Netgear, and TP-Link all publish hardening checklists, and every setting they recommend takes just a few clicks.
This guide walks through the five router settings that actually matter, in the order you should change them. You need about fifteen minutes, a device already on your network, and your router’s admin address — usually 192.168.1.1 or 192.168.0.1, printed on the label under the unit. The steps apply to any brand, including mesh systems that are managed through a phone app.

Step 1: Change the Default Admin Login
The admin login controls the router itself, and default credentials for nearly every model are listed openly on the web.
- Type your router’s IP address (from the label) into a browser on a connected device.
- Sign in with the current admin username and password.
- Open Administration, System, or Management, depending on the brand.
- Set a new admin password that you do not use anywhere else, and store it in a password manager.
- Save and log back in with the new credentials to confirm they work.
Our pick for this guide: ASUS RT-AX86U Pro WiFi 6 Router
Supports WPA3 and automatic firmware updates, which the older routers in most homes simply cannot enable.
Step 2: Switch Encryption to WPA3 (or WPA2-AES)
Encryption decides whether neighbors see gibberish or your actual traffic. WPA3 is the current standard; WPA2 with AES remains acceptable for older devices.
- Open the Wireless or Wi-Fi settings section.
- Set the security mode to WPA3 Personal, or WPA2/WPA3 mixed mode if some older devices drop off.
- Never leave the network on WEP or WPA-TKIP — both are broken standards.
- Create a passphrase of at least 12 characters; a short sentence works well.
- Save, then reconnect your devices with the new passphrase.
Step 3: Update the Router Firmware
Firmware patches close the security holes attackers actually use. If you have never done it before, our step-by-step guide on how to update router firmware safely on any brand covers every major interface.
- Find the Firmware Update or Router Update section, usually under Administration.
- Run the built-in update check and install any available version.
- Enable automatic updates if the option exists.
- Let the router reboot fully — never unplug it mid-update.
Step 4: Disable WPS and Remote Management
WPS lets devices join with an 8-digit PIN that can be brute-forced, and remote management exposes your admin page to the whole internet.
- In the wireless settings, turn off WPS entirely.
- Under Administration or Advanced, disable Remote Management (sometimes called Web Access from WAN).
- If you forward ports for gaming or a home server, review them — our guide to port forwarding on any router explains which rules are safe to keep.
- Save and reboot the router.
Step 5: Set Up a Guest Network
A guest network keeps visitors and cheap smart-home gadgets away from the computers that hold your files.
- Enable the Guest Network option in the wireless settings.
- Give it a different name and its own strong passphrase.
- Turn on client isolation (often labeled “guests cannot see each other or the LAN”).
- Move smart plugs, bulbs, and TVs onto the guest network.

Common Mistakes to Avoid
A few habits quietly undo all the work above. Watch for these:
- Securing the router but not the extender. Range extenders keep their own admin logins. If you use one — or you are choosing between an extender and stronger hardware after reading our guide on how to extend Wi-Fi range in your home — change its default password too.
- Reusing the admin password as the Wi-Fi passphrase. Anyone you share Wi-Fi with can then reconfigure your router.
- Keeping a router that no longer receives firmware. Once a manufacturer ends support, security holes stay open forever. If yours is out of support, start with our roundup of the best long-range Wi-Fi routers or, for larger houses, the best mesh Wi-Fi systems for multi-story homes.
- Ignoring the connected-devices list. Skim it monthly; unknown devices mean it is time to change the passphrase.
Frequently asked questions
What is the single most important Wi-Fi security setting?
Encryption. Set your router to WPA3 Personal, or WPA2-AES if some devices refuse to connect, and pair it with a passphrase of at least 12 characters. Every other setting builds on that foundation.
Should I hide my Wi-Fi network name (SSID)?
Hiding the SSID adds almost no real security, because scanning tools still see the network. A strong passphrase and modern encryption protect you far better than an invisible name.
How often should I update my router firmware?
Check every three months, and turn on automatic updates if your router offers them. Manufacturers such as ASUS, Netgear, and TP-Link ship security patches several times a year.
Is it safe to leave WPS enabled?
No. The WPS PIN method has a known brute-force weakness, which is why manufacturer documentation recommends disabling it once your devices are connected. Turn it off in the wireless settings page.