All cheatsheets

Cheatsheet · beginner

Router hardening

Default-kill checklist for consumer and prosumer home gateways.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

home-network
router
defense

Admin plane

Command
# Change default admin password to long unique secret
Command
# Disable WAN/remote administration
Command
# Disable Telnet; prefer HTTPS admin on LAN only
Command
# Update firmware; note version in asset sheet

Wireless

Command
# WPA2/WPA3-Personal; long passphrase; no WEP/WPA-TKIP
Command
# Disable WPS (push-button and PIN)
Command
# Separate guest SSID; client isolation on
Command
# Prefer unique SSID; avoid personally identifying names

Services & exposure

Command
# Disable UPnP if unused; audit remaining port maps
Command
# Avoid DMZ host to a PC
Command
# Prefer VPN (WireGuard/Tailscale) over open RDP/SSH ports
Command
# Optional: custom DNS → Pi-hole / AdGuard Home

Checklist

  • No default passwords anywhere on path
  • WPS off confirmed after reboot
  • WAN admin confirmed off from external check
  • IoT plan: guest/VLAN or documented exception