This is a read-only archive. No new posts or registrations. Privacy Page
Software

How do I secure my router?

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have Windows XP and I have a Linksys router version 5 and I would like to secure or find out how to make my router secure. I use Port 1 for my xbox 360 to connect to the internet. My Modem is a Webstar modem provided by Road Runner High Speed Online (Time Warner Calbe. The one who set up my router was a independent tech. I know very little about routers and I've never set one up or anything. So are there sets specifically for my router to get it secre? Also I heard by listening to Kim Komando: komando.com that there's a way to "lockdown your wireless network. I'm not sure where that is on her site. I did check the forum I was told about earlier today to make sure I'm sure wiht regards to checking for malware. Basically it called for scanning with software that I already have. Anyway I thought there might be something on this NetBios message my firewall came up with in that incident. So I typed in NetBIOS hack. And I found out a ton of things people can do with this netbios. Since it has to do with the LAN and that would mean my rotter that's why I want to be secure with it. I do have a ZoneAlarm firewall and all my ports are silent according to the ShieldsUp site I was recommended to go to a few threads earlier. So my Firewall is covering the ports. Just would like my router good too. Thanks.
There are a couple basic things that everyone should do.

1. Change the default password and, and if allowed, the administrator user name - even the wannabe hackers know all the default names and as reported here, a new variant of the Zlob Trojan does too!

2. Change the default SSID or Network Name - same story.

3. Disable SSID Broadcasting - many routers come with SSID Broadcasting enabled. This allows anybody, including the badguy to drive down your street and see your network. Why advertise you have a wireless network unless you run a wireless cafe?

4. Use MAC Address Filtering - every network device, such as a network interface card, router, cable modem, etc. has (is supposed to have) a unique MAC address - by using MAC address filtering, you instruct your router to only let that device through.

5. Enable encryption - use the highest level that all your devices support.

6. Use Ethernet - most wireless routers include a 4-port Ethernet switch - use that for your fixed (not portable) networked computers. This also ensures you will have access to your router's security settings should wireless access fail.

Will these steps eliminate all risks? NO! But locks are to keep honest people honest. If a bad guy wants in, he's coming in - depending on his tools and skills - and demeanor. But like all bad guys (except for the pure pros) they seek opportunities for easy pickings. Keep your garage door open at night with no lights on and someone is going to see that as easy pickings. Keep the door closed, locked and well lit, 99.9% of the badguys are going to move on. They certainly are not going to park in a strange car out front and point an antenna at you or your neighbor's house without attracting unwanted attention.
Well, I suggest you check your router manual. In there, you should see how to log into your router's setup menu with your browser and make the necessary changes. If you need help from there, we will need to know the exact model number of the router. If you did not get a hard copy of the manual, it will be on the CD that came with the router, or you can download a copy from the maker.
I've looked in the file drawer I have with all the computer stuff in it and I don't think the independent tech left the disk and manual with me. He just bought the router and did the installation. And took the rest with him. I mean he very well could've secured the router, but I guess without the disk or manual there's no way of knowing. Dang. I guess I'll have to ask him.

I guess without the disk or manual there's no way of knowing. Dang.

That's why I said,

or you can download a copy from the maker.

This is actually better because the on-line version will have any corrections or updates included. So go out to Linksys - at the top is the Downloads section and navigate to your specific router and download the manual from there.

He just bought the router and did the installation. And took the rest with him.

You mean he did not show you how to access the router's menu system? How to change the password to something he does not know? If so, that's bad, and, IMO, his manager needs a talking to. No one but you should know how to access the router's menu.
I found out my Model: WRT54GS v.5 Also I located the manual on the site. It's really long. 137 pages to be exact. I learned in order to access the router's settings you have to press Star>Run>type cmd>then type ipconfig By default the address for your router is 192.168.1.1 Type this into your browser. You then get prompted for Authentication. So you type in admin for username and admin for password. Once in I went to Administration and found there already was a password in the menu there. I only showed it with stars. But the stars were 12 characters long. Is the password to change the Authentication or is it the one in the Administration menu? Also hypothetically someone were to get into your network what can they do? Can they only hack it if they're in your neighborhood or could someone get into your router and be states away? Yeah I'll talk to the tech. With the amount of time that's passed I hope he remembers what he did. So someone can get into your router even though you have a firewall up?
Do not put any value to the "12" stars (asterisks). There being 12 is to do exactly what it did - confuse the one attempting to see what the password is. The asterisks are there in case someone is looking over your shoulder. The fact you got in says you used the correct password - in this case, the Linksys default of "admin". So once in, change it - NOW! - to something you want - just don't write it down, or forget it. At this point, you don't need to talk to the tech - you are already in.

By the way - "authentication" is the process the system uses to verify you have the proper authorization (credentials) to gain access - that authorization is verified by you entering the proper user name and password. At this point, you have proven to the router you are the administrator of that device.

If someone gets into your network, the damage they can do then depends on the security you have set up for each computer on your network. This is why every computer should also have a software based firewall running on each computer, and complete set of anti-malware tools installed, current, and running. Remember, badguys can come in from two directions, the "trusted" side, that is, from your network (anything on your side of the router), or from the Internet side. If from the Internet side, they could be on the other side of the world.

What happens often with unsecured wireless networks is the badguy then uses your Internet connection to distribute his malware. This is likely done by sending out spam (with malicious cargo) through your IP (the one assigned to your gateway (cable/DSL Modem)) by your ISP. This can cause your ISP to shut down your access and give you a bad name. Not cool.

The reason why wireless is so dangerous is because the badguy can be across the street, in the house or apartment next door, or the floor below and use your wireless connection. Or they may use highly directional antennas which allow them to be several hundred yards away or farther.

So someone can get into your router even though you have a firewall up?

Yes, BUT - each layer of defense you add, the harder it is for him to come in so I don't want folks to starting getting paranoid. Having a router is a huge barrier to most hackers. Then having a firewall on each computer is another tough barrier to crack. At this point, 99.9% of the bad guys are going to move on to easier pickings.

Unless you, that is specifically you have something that specific badguy wants and knows you possess, you are going to be safe - assuming you, and every user on your network, are diligent at practicing safe computing.

See the Practicing Safe Computing section of my sticky, Cleaning Out Malware for more information.

That said, just as a determined professional burglar can bypass security alarms and the best locks, if a pro wants in, he is probably going to get in. But again, unless you have something very valuable that he knows you have, like industrial or military secrets, he's not going to waste time on you. So your goal is to keep out the wannabes and nosy neighbors.
Thanks. A few more questions though. I looked up different types of encryption. Since that's one of the 6 steps you talked about. Am I correct that the 3 types are WEP, WAP, and WAP2? Are there more? According to Youtube you can run WAP on the Linksys router, but what about WAP2? Also, in the settings menu for the router what is MTU? It's set to Auot. Host Name and Domain Name are blank in the setup menu. Are they supposed to have to have things in them. Subnet Mask has 255's in it. What's that? DHCP Server is enabled. DDNS, MAC Address Clone, Advanced Routing? In Advanced Routing is set to 10. In the Wireless Tab Wireless Network mode is set to mixed. Wireless Channel is set to 6 - 2437GHz, Wireless SSID Broadcast is enabled. In wirless security it's disabled. Besdies WEBP, WPA, WPA2, I also see WADUS. It's the only option in that menu. Wireless MAC Filter is disabled. Advanced Wireless Settings: Basic Rate, Transmission Rate, CTS Protection Mode, Frame Burst,, Beacon Interval, DTIM Interval, Fragmentation Threshold, RTS Threshold. Do I do anything to any of those, AP Isolation. In the Security tab Filter Internet NAT Redirection is unchecked. Al other options in the Firewall menu are checked to filer. In the VPN menu IPSec Passthrough, PPTP Passthrough, L2TP Passthrough are all enabled. Access Restrictions tab has a submenu called Internet Access. Should I change anything there? Gaming and Applications should I change anything there? In Administration besides chaning the password, do I disable wireless access? Access Server is set to HTTP. Do I set it to HTTPS? Remote Management is disabled, DPmP is enabledisabled. I ask all of this because I realy only use the router to share my internet with my modem and xbox 360. The xbox is connected to the rotuer by way of a ehternet cable. It's the one home computer only. I don't have multiple computers.
Wow - that's too much for a simple forum format - especially since most, if not all is in your manual. But I will answer some and you can find some more answers clicking on the Learning Center button on the Linksys website. And finally, use Google - just enter the term you want to know more about.

There are more encryption types, but for home routers, you have listed the most common. You should use the highest the can support all your devices going through the router.

DHCP (Dynamic Host Configuration Protocol ) along with NAT (network address translation) is what makes home routers nice. Together they automate the process to assign unique IP addresses to each device attached to your network. This is what allows you to have more than one computer sharing the single IP assigned to you by your ISP. It also allows you to simply connect a new computer and automatically get an IP address assigned to it.

I realy only use the router to share my internet with my modem and xbox 360.

That is what you use it for, but because your computer and your XBOX have been assigned their own IP address that are different from that assigned by your ISP, this, in effect helps hide your IP addresses from the outside. That is a HUGE security advantage and why I recommend folks with just a single networked device get behind a router too.

You can might disable DHCP and then assign "static" IP addresses to your devices. Many experts recommend this as you can then use addresses are not the standard defaults used by your routers maker. This, along with MAC filtering allows you better control over specific devices that can attach to your network.

The other settings are for advanced users and can be used to set up more advanced networks options. In your case, you can just leave them in their default settings.
For those who would like to see what we are talking about in a vid, there is this youtube vid with this guy who does exactly what we did: http://youtube.com/watch?v=ZH6bLu3ri1c

The thing is he runs out of time and does not get to show you how to set up the WPA. If anyone finds the second half please post it so I can do it too. That way I won't have to look this all up.

One other thing, once I click save changes is that it? Internet should be fine? I remember the tech when you did the setting up he was on the phone with my isp and they told him the ip address to type in for the modem. Do I have to type that in and the new password everytime I make a change or just make a change and click save settings?

Sorry for the 50 billion questions before. I know some of this stuff I should look up on my own, but I just want to be sure of what I'm doing. I'm the cautious mathoughtical type who wants to know all that he can before jumping and chaning stuff.

One other thing, once I click save changes is that it? Internet should be fine?

Yes.

I remember the tech when you did the setting up he was on the phone with my isp and they told him the ip address to type in for the modem. Do I have to type that in and the new password everytime I make a change or just make a change and click save settings?

No, you should not have to do that. Actually, I am surprised he had to as most ISPs dynamically assign IPs. Perhaps that was just for the initial setup. At any rate, you should probably record the IP assigned by your ISP somewhere just so you remember it. That is the IP the world sees as you. Your password is set so you will never have to re-enter it once you are in the menu.

Sorry for the 50 billion questions before. I know some of this stuff I should look up on my own, but I just want to be sure of what I'm doing.

That's okay and a wise precaution.

Oh, and don't believe everything you find on You Tube. TechAnvil's stuff is fine, but not everyone is sincere is helping folks.
Well let me know if you find the second half of tha vid where he covers WPA encryption. My ISP assigns static ip addresses. And is this Tech Anvil one of those guys where if you send him a message he might or might not get back to you since he's popular and gets hundreds of messages a day types? Thank you very much. I'll keep you posted on the outcome and ask if I ned further help.

And is this Tech Anvil one of those guys where if you send him a message he might or might not get back to you since he's popular and gets hundreds of messages a day types?

I don't know him so your guess is as good as mine. And since I only reviewed that link you provided I guess I should recant what I said and instead of saying his "stuff is fine", I should have said that particular clip is fine.

Well let me know if you find the second half of tha vid

Well, sorry, but I'm not looking for it.
I understand. You don't want to look for the other because like you said not all of his stuff is fine. So it would be bad posting something that might not be good to do right? I successfully disabled the SSID Broadcasting and made a 30 character password and saved it to a text file on my flash drive.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI