Standard Router Settings

- Change the name of your default home network
- Don’t make it a recognizable name
- Don’t put your name it it
- No street names
- If you are in a congested area, you might want to hide your network and turn off SSID. Places like NYC, SFO, Tokyo etc
- Enable network encryption SPA2 AES or soon to be out WPA3
- Enable guest network for your guests.
- Set a strong password for your admin user name and wireless access
- Disable remote access for router
- Always keep routers firmware up to date
- Disable remote access for router
- Disable IPv6. Its routable and not behind NAT – Cover greater detail later
Extreme Router Settings
- You can change the default IP address on wireless router
- Turn off DHCP and set IPs manually
- Allow network device ONLY by Mac Addresses
- Turn off when not home
General Network Securing
- If possible center the router in your home so it doesn’t go outdoors as far.
- Connect to your network via an Ethernet Cable
- Gives a better overall connection and doesn’t use wireless bandwidth
- Wireless steals bandwidth from others
- Add a firewall to your network if you feel the need – Advanced
- Turn off unnecessary features
- Bluetooth
- Wireless networks on your desktop when it’s connected to an ethernet network
- Don’t use an Alexa, Google or Apple Home unit(s)
- They listen to everything
- Police Requests To Access Your Smart Speaker Are Up 72% Since 2016
- Google admits to listening in on private conversations via Assistant
- Amazon Staff Are Listening To Alexa Conversations — Here’s What To Do
- Apple’s hired contractors are listening to your recorded Siri conversations, too
What is NAT (network address translation)
IPv4 & IPv6
Autoconfig of IPv6 can leak your MAC address to identify your individual computer
NAT only works with IPv4
- IPV6 vs IPV4: what are they, what’s the difference, which is most secure?
- https://www.sophos.com/en-us/security-news-trends/security-trends/why-switch-to-ipv6.aspx
Optional Additions Covered Later
Add a VPN to your individual computer & mobile device
Add a Pi-hole to your whole house network