All cheatsheets
Cheatsheet · beginner
Router hardening
Default-kill checklist for consumer and prosumer home gateways.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
home-network
router
defense
Admin plane
Command
# Change default admin password to long unique secret
Command
# Disable WAN/remote administration
Command
# Disable Telnet; prefer HTTPS admin on LAN only
Command
# Update firmware; note version in asset sheet
Wireless
Command
# WPA2/WPA3-Personal; long passphrase; no WEP/WPA-TKIP
Command
# Disable WPS (push-button and PIN)
Command
# Separate guest SSID; client isolation on
Command
# Prefer unique SSID; avoid personally identifying names
Services & exposure
Command
# Disable UPnP if unused; audit remaining port maps
Command
# Avoid DMZ host to a PC
Command
# Prefer VPN (WireGuard/Tailscale) over open RDP/SSH ports
Command
# Optional: custom DNS → Pi-hole / AdGuard Home
Checklist
- No default passwords anywhere on path
- WPS off confirmed after reboot
- WAN admin confirmed off from external check
- IoT plan: guest/VLAN or documented exception