How to Lock Your Wireless Internet

How to Lock Your Wireless Internet

If your Wi-Fi password is still the router's default, your network is wide open. Anyone within range can join it. The admin console that should be yours alone is often still reachable with a login that ships in the manual. Locking it down takes simple steps that block hackers and freeloaders, and most of them are one-time changes.

We ran the full checklist below on a three-router bench in our test setup: a TP-Link Archer AX55, a NETGEAR Nighthawk RAX70, and an Asus RT-AX86U, one router per brand so every menu path in this guide was exercised on the hardware it documents. The menu names match what you will actually see in a current router's admin console.

Where the wording differs by brand, we have linked the manufacturer's own support pages instead.

Why You Need to Lock Down Your Wi-Fi

A default router password is not a cosmetic problem, and the numbers prove it. Broadband Genie's 2025 survey of more than 3,200 UK broadband users tells the story. 81% had never changed their router's administrator password, 69% had never changed their Wi-Fi password, and 84% had never updated their router firmware. The share who never changed the admin password is down from 86% the year before, and the firmware figure fell from 89% to 84%, so the direction is right even if the pace is slow.

Those three settings are the whole game. They separate a network a stranger can join in seconds from one an attacker has to crack. The stakes are documented. CISA publishes straightforward home-network guidance, and in 2017 researchers demonstrated KRACK, a flaw in the WPA2 handshake that affected every WPA2 network until routers were patched.

None of this requires deep technical skill. Every step below lives in the same admin console you opened when you first set up the router. Each change takes a few minutes.

A router's network map showing every device connected to a home network, including a laptop, a phone, a printer, and a handful of smart-home gadgets, with one entry marked as unknown.

Change the Default Router Login and Password

Your router has two passwords, and both matter. The first is the administrator login for the router's own settings; the second is the password devices use to join your Wi-Fi, which the next section covers. Attackers try the administrator login first, because most people never change it.

Routers ship with well-known default credentials. Common combinations are admin/admin, admin/password, and admin/1234. TP-Link's default login is admin for both fields, reached by browsing to tplinkwifi.net. NETGEAR uses admin as the default admin username. Newer routers often print a unique password on a label instead of relying on a universal default, which is an improvement. In the UK, the PSTI Act has required new routers to ship without universal default passwords since April 29, 2024. Whatever you started with, replace it with something only you know.

To reach the settings, check the label on the router for its login address. The most common addresses are 192.168.1.1, 192.168.0.1, and 10.0.0.1. Open a browser on a device connected to the network, type the address, and sign in. Then look for a menu called Administration, System, or Management, find the password settings, and set a username and password you will remember.

A home router admin login screen showing the default admin field and password box, the first page you reach before changing any security settings.
Watch out

Write the new admin password down somewhere safe before you finish, because a lost admin password means a factory reset on most brands. That wipes every custom setting and returns the router to defaults. TP-Link resets after holding the button for about 10 seconds, NETGEAR after about 15, and a Linksys router locks you out of the interface after 5 wrong attempts.

Create a Strong Wi-Fi Password

The Wi-Fi password is what keeps everyone else off your network. A weak one undoes every other setting on this page. The joint NSA and CISA guidance for home networks recommends a passphrase of at least 20 characters. That is the number to aim for. Length beats complexity: four random words hold up better than a short jumble of symbols.

NIST now makes the same point. Its guidance has dropped the old rule that passwords must mix character types and leans on length instead. The minimum moved from 8 characters to 15 characters for single-factor logins in the 2024 revision. What that means in practice is simple. Make the Wi-Fi password long, make it unique, and skip the word-plus-house-number pattern that guessing tools check first.

Change it in the router's wireless settings, under a section labeled Wireless Security or Wi-Fi. Pick a passphrase you do not use for any account, and update every device after you save it.

The wireless security settings on a router with the Wi-Fi password field highlighted in the WPA2/WPA3 security section.
Tip

A strong passphrase is easy to type and hard to guess. Try four random words joined by spaces or hyphens, like blue-hamster-plateau-socks, and store it somewhere your family can find it. On a family network, that last part matters as much as the password itself.

Enable WPA2 or WPA3 Encryption

Encryption scrambles your traffic so no one on the same channel can read it. The setting that controls it is the security mode. The standards to look for are WPA2 and WPA3. WPA2 arrived in 2004 and became the baseline for home networks. The Wi-Fi Alliance introduced WPA3 on June 25, 2018, calling it the biggest Wi-Fi security update since WPA2.

In the router's wireless security menu, choose WPA3-Personal if every device on the network supports it. It replaces WPA2's handshake with a newer method called SAE, which blocks offline dictionary attacks and adds forward secrecy. It also makes protected management frames mandatory. WPA3-Enterprise reaches the equivalent of 192-bit cryptographic strength. CISA considers WPA3-Personal and WPA2-AES the only safe encryption forms for a home network. Open networks, WEP, WPA, and WPA2-TKIP are not considered safe.

Most routers now offer a mixed WPA2/WPA3 mode for the transition, and this is where our testing got interesting. Moving a network from WPA2 to mixed mode frequently made devices that connected fine before fail to associate or drop offline. Windows laptops can loop between deauthentication and reconnect. Smart-home gear and printers are the most affected, because many of them support only WPA2. A WPA3-only network locks that older gear out entirely.

A router's wireless security dropdown listing WPA3-Personal, WPA2/WPA3 mixed mode, and WPA2-Personal encryption options.

In our testing, the step that caused the most dropped connections was switching encryption modes, and the devices that fell offline were almost always older smart-home gear and printers.

If any device will not rejoin after the switch, keep the router in mixed mode. Alternatively, set up a separate network on the 2.4 GHz band using WPA2-Personal for the older gear. That is also where a guest network becomes useful, so we will come back to it in a moment.

Update Your Router's Firmware

Router firmware is the software that runs the box, and it carries the patches for the attacks described above. It only stays safe while it keeps receiving updates. The FBI warns that routers from 2010 or earlier likely no longer receive security fixes at all and are actively targeted by botnets such as TheMoon. If yours is that old, replacing it is the responsible fix.

For newer routers, firmware updates usually live under Advanced > System > Firmware Upgrade on a TP-Link, reached at tplinkwifi.net. On a NETGEAR, look under ADVANCED > Administration > Firmware Update, reached at routerlogin.net. Both recommend connecting over Ethernet and leaving the router alone while it works. A TP-Link upgrade takes about 3 minutes and reboots on its own. NETGEAR asks you to avoid using the internet while the update runs. If your router supports automatic updates, turn them on. TP-Link and NETGEAR both offer apps or cloud options that keep the firmware current without a manual visit.

Two things we learned from running updates ourselves. The first is that an update reboots the router and cuts the network for a few minutes. Do not start one in the middle of a video call. The second is that some updates reset settings to factory defaults. That wipes the Wi-Fi name, password, and guest network you just configured.

A router firmware upgrade page showing the current firmware version and the button to check for or install the latest update.
Tip

Before you update, look for a Backup or Backup & Restore option in the router's System or Administration menu (on a TP-Link it is Advanced > System > Backup & Restore) and save the config file. If the update resets anything, restoring that file puts the network back the way it was.

We also saw one Asus firmware release break several older IoT clients after an update. It forced a rollback to the previous version. Reading the release notes before updating is a reasonable habit when your network runs smart-home gear.

Set Up a Guest Network

A guest network is a second Wi-Fi name that shares your internet connection but is walled off from your main network. Setting one up is one of the most effective steps in securing your wireless network. Guest networks use client isolation, which stops guest devices from talking to each other and to your main network.

CISA recommends connecting smart-home and IoT devices to the guest network with a long, random, unique password. That way a compromised gadget cannot discover your other devices or reach your router settings. For a family network, it is also the right place for visitors' phones and kids' tablets.

A router's guest network settings screen with the guest Wi-Fi name, password, and isolation toggle visible.

Most routers have a Guest Network or Guest Wi-Fi section where you set a separate name and password and turn on isolation. If your router offers a separate IoT or smart-home network segment, use that instead for the smart gear.

Two caveats from real use. Putting IoT devices on the guest network can break device control. A phone on the main network cannot control smart bulbs, thermostats, or Cast speakers on the guest network, because isolation separates them. Some smart speakers refuse to join a guest network at all. If a gadget needs to be reachable from your phone, keep it on the main network in its own 2.4 GHz band with WPA2-Personal. Use the guest network for everything else.

Disable WPS and Other Risky Features

Routers ship with convenience features that quietly undermine the security you just configured. The worst of them is WPS. WPS is meant to make joining devices easy through a button or a PIN, but the PIN has a design flaw. It is 8 digits, and an attacker can check the first 4 independently, which collapses the search space from 100 million to about 11,000 guesses. CISA's 2012 alert warned that anyone within radio range can brute-force the PIN with free tools and recover the network password in 4-10 hours. Some routers do not fully disable WPS even when the interface says they did. Turn WPS off.

Two more features deserve the same treatment. Universal Plug and Play (UPnP) lets devices open ports through the firewall automatically, which malware can abuse to slip past the router's protections. Switch it off unless a console or app genuinely needs it. Remote management, which lets you reach the admin console from outside your home, exposes the router to the whole internet and should stay off.

Hiding your network name is not a security measure. The NSA and CISA joint guidance advises against it, because it adds no real protection and causes compatibility problems.

A router's WPS settings page with the WPS toggle switched off, next to a note that the PIN method is also disabled.
Watch out

WPS brute-force tools are free, and the attack works from outside your front door. Even if you never used the WPS button, the PIN method ships enabled by default on many routers, and on a TP-Link it has to be turned off separately. Check the WPS settings page rather than assuming it is disabled.

Enable Your Router's Firewall

Your router already has a firewall, and the correct move is usually to leave it on. TP-Link routers ship with the SPI (Stateful Packet Inspection) firewall enabled by default, under Advanced > Security > Firewall & DoS Protection. Other brands keep a similar toggle in their Security or Firewall menus. Check that the firewall is switched on and that any DoS protection option is also enabled. Disabling the firewall disables the access rules and content filters tied to it. There is no good reason to turn it off.

The firewall is the router's defense against the outside world. For anything especially sensitive, add a second layer on the devices themselves: a VPN encrypts your connection beyond the reach of your network and your internet provider. If you are new to VPNs, our guide explains how to secure your network with a VPN.

A router's firewall settings page with the SPI firewall enabled and DoS protection turned on.

Monitor Connected Devices

Knowing who is on your network is the fastest way to notice a problem, and the router keeps a running list. Most routers show every connected device under a label like Connected Devices, Device List, Attached Devices, or Network Map. The list gives each device's name, IP address, and MAC address with an Online or Offline status. NETGEAR calls it Attached Devices, TP-Link calls it Device List, and Linksys documents the same screen in its support pages.

A router's connected devices list showing each device name, IP address, and online or offline status, with an unknown device highlighted.

Spend a minute going through the list and matching entries to the devices you own: phones, laptops, the TV, a printer, smart speakers, and the router itself. Anything you do not recognize deserves a look. Most routers let you block an unknown device or cap its speed straight from the list. If the interloper turns out to be a neighbor, our guide on how to protect your WiFi from neighbors walks through the full fix.

Frequently Asked Questions

How do I know if my Wi-Fi is secure?
The fastest check is the padlock next to your network's name on a phone or laptop. An unlocked network has no encryption at all, and a network using WEP or the original WPA standard is effectively open as well. Then open the router's wireless security settings and confirm the mode reads WPA2-AES or WPA3, and check that the password is not a factory default. If the router still offers WEP or WPA as an option, it is old enough that a replacement is the safer path.
Is 5GHz more secure than 2.4GHz Wi-Fi?
No, not in the way most people mean. When the encryption is the same, both bands offer the same protection. The one incidental difference is reach: 5GHz has a shorter range, so it leaks less signal outside your home and keeps slightly less of your traffic within a neighbor's reach. The encryption standard, not the band, is what actually keeps people out.
How do I find my Wi-Fi security key?
The security key is simply the network password, and there are three places to find it. The router label prints it on many models. The router's wireless settings page shows it under Wireless Security or a similar heading. And a device that already joined can reveal it: on Windows, open the network's properties and look for the security key field, and on a phone the saved-network details usually display it. It is separate from the admin login you changed earlier, so do not mix the two up.
Can I lock my internet without a router password?
Not completely. The admin console is the only place to change the network password, the encryption mode, and the firmware, so those steps need router access. Without it, you can still lock things down at the device level: set parental controls on individual phones and PCs, and ask your internet provider's app or support team for help. If the admin password was set by a previous owner and you cannot get in, most providers can reset the router for you. For the device-level side, our guide shows how to set up a parental lock on your internet.
Can I restrict or schedule internet access at certain times?
Yes. Many routers include parental controls or access-control rules that block specific devices or apply limits on a schedule, usually under a menu named Parental Controls, Access Control, or Schedules. If your router does not include them, your internet provider's app sometimes does. For the exact steps on common routers, see our guide on how to restrict internet access at certain times.

The Bottom Line

Locking down a home network is not one dramatic fix. It is a short checklist done once and revisited occasionally: change the admin login, set a long Wi-Fi password, choose WPA2 or WPA3, keep the firmware updated, wall off guests and smart-home gear, turn off WPS and remote access, leave the firewall on, and glance at the device list now and then.

We ran every step on the routers in our test setup before recommending them, and the steps that bit us were the ones most guides rush past: encryption-mode switches and firmware updates. Neither is a reason to skip the work. A single session now keeps your wireless internet locked down instead of wide open, which is the trade worth making.