EN
English
Русский

How to Segment Your Network: Guest and IoT VLANs

On a flat network, every device can reach every other one. Your work laptop, the file storage, a visitor’s phone, and a ten-dollar smart plug all sit on the same segment with nothing between them. Segmentation breaks that single space into separate zones so that a problem in one does not become a problem everywhere. This guide explains what a VLAN actually is, how to split guests and smart-home devices onto their own segments, the catch that trips up most people with IoT, and how to confirm the isolation really works. Everything here is framed for a network you own and run.

What a flat network is

A flat network is one where every device shares a single segment: one address range, handed out by one router, with no internal boundaries between the devices on it. It is the default almost everywhere – plug things into the same router or join them to the same Wi-Fi, and they all land on the same network, able to talk to one another directly. The alternative is a segmented network, divided into separate zones that cannot reach each other except through rules you set. That separation can be physical, with genuinely separate equipment for each zone, or logical, where one set of hardware carries several isolated networks at once – the approach this guide uses, built on VLANs. Most real networks sit somewhere on the line between fully flat and carefully segmented; a home router’s “guest network” switch is the smallest step off the flat end.

Why a flat network is a risk

The case for segmentation is about containment, not paranoia. A cheap smart device running firmware that stopped getting updates years ago, or a guest’s laptop carrying something unpleasant, is a foothold. On a flat network that foothold can see and reach everything else – the storage with your files, the other computers, the printer with its saved credentials. Segmentation does not make any single device more secure; it limits how far a compromise can spread once it happens. You are shrinking the blast radius in advance, because the cheapest time to contain a problem is before it exists.

What a VLAN actually is

A VLAN (virtual LAN) is a way to divide one physical network into several logically separate ones. Devices on different VLANs behave as if they were on entirely different networks: traffic only passes between them where a router or firewall is explicitly told to allow it. Each Wi-Fi name (SSID) can be mapped to its own VLAN, so a single set of access points can serve a trusted network, a guest network, and a device network at the same time, each kept apart from the others. If the idea of separate address ranges per segment is new, what an IP address, subnet mask, and gateway are covers the groundwork.

Three segments that cover most needs

You do not need many segments – you need the right few:

  • Trusted: your own computers, phones, and file storage. The things you actively manage and keep updated.
  • Guest: anything you do not control. Visitors, contractors, a friend’s tablet.
  • IoT: smart plugs, bulbs, cameras, TVs, and other appliances – often cheap, rarely updated, and the least trustworthy hardware in the building.

Some networks add a fourth for work-critical equipment, but three is a sensible default. Each extra segment is something you have to address, configure, and maintain, so stop at the number you will actually look after.

The guest segment

A guest segment is the easiest win. Map a separate SSID to a guest VLAN that reaches the internet but not your other segments, and turn on client isolation so guests cannot see one another either. Visitors get working Wi-Fi; your trusted devices stay invisible to them. Many home routers offer this as a one-switch “guest network” feature, which is a simple, preset version of the same idea – see how to set up a guest Wi-Fi network for the consumer-grade route.

The IoT segment and its catch

Isolating smart devices is where good intentions meet a real obstacle. The point of an IoT segment is to keep under-maintained gadgets away from your trusted devices. The problem: you usually control those gadgets from a phone app, and your phone lives on the trusted network. The automatic local discovery that smart-home apps rely on to find a device is designed to work within one network and does not cross between isolated segments. Put the bulb on its own VLAN and the app on your phone may simply stop finding it.

There is no magic fix, only honest trade-offs:

  • Keep the controllable devices on the trusted network and isolate only the truly headless or risky ones (an old camera, a device from a vendor you do not trust).
  • Use a router or controller that can bridge local discovery across segments – many prosumer and business systems have this as a feature you switch on for specific networks.
  • Put your phone and the smart devices on the same segment, and isolate everything else around them.

Decide which of these you can live with before you start moving devices, not after the lights stop responding.

Set the rules between segments

Segments are only as separate as the rules between them. The default between two segments should be to deny traffic, then allow only what is genuinely needed – for example, the trusted segment may need to reach the IoT segment to control devices, but the IoT segment almost never needs to start a conversation with the trusted one. This is enforced where the segments meet, at the router or firewall that routes between them. Without those rules, separate VLANs that all route freely to each other are separate in name only.

What you need to do this

Full VLANs require gear that understands them: a router, access points, and any switches that support VLAN tagging. Prosumer and business equipment handles this directly; a growing number of mesh systems expose multiple isolated SSIDs as well. If your hardware only offers a single “guest network” toggle, that is still worth using – it delivers the most important benefit, keeping untrusted devices off your main network, without any VLAN configuration at all.

Verify the isolation actually works

A segment you have not tested is a guess. Confirm it from the inside:

  1. Connect a phone to the guest or IoT segment.
  2. Open the IP Info tool in IP Tools (Android) or WiFi Tools (iOS) and confirm this segment has its own address range and gateway, separate from your trusted network.
  3. Run the LAN Scanner from that same segment. If isolation is working, the scan should show only what belongs on that segment – your trusted computers and storage should not appear. If they do show up, traffic is crossing where it should not, and your rules need another look.

Repeat the scan from each segment. Seeing your trusted devices from the guest network is exactly the result segmentation is meant to prevent. For reading a device list, see how to see who is connected to your Wi-Fi and the LAN Scanner help page.

FAQ

What is the difference between a guest network and a VLAN?
A guest network is a simple, preset single segment built into many home routers. A VLAN is the general mechanism for creating several isolated segments and deciding exactly what may pass between them. A guest network is essentially one VLAN with the choices already made for you.

Why did my phone stop controlling a smart device after I moved it to a separate network?
The automatic local discovery that smart-home apps use to find a device does not cross between isolated segments. Keep controllable devices on the same segment as your phone, or use a router that can bridge discovery across the segments you choose.

How do I check that my segments are really isolated?
From a device on the guest or IoT segment, confirm with IP Info that it has its own address range and gateway, then run a LAN scan – you should not see your trusted devices. If you do, traffic is leaking between segments and the rules need fixing.

Do I need business-grade hardware to segment my network?
For full VLANs, yes – you need VLAN-capable gear. But many home routers include a guest-network toggle that delivers the single most valuable outcome, keeping visitors and untrusted devices off your main network, with no VLAN setup required.

How to Optimise Wi-Fi for Apple Devices (iPhone, iPad, Mac)

iPhones, iPads, and Macs make their own decisions about when to switch access points and which band to use, and those decisions follow consistent rules. Design a network with those rules in mind and Apple devices stay connected smoothly as people move around; ignore them and devices drop, stall, or cling to a distant access point. The plan below distils Apple’s deployment guidance into practical steps for an office, a school, or any space full of Apple hardware.

Keep the number of network names small

Every Wi-Fi name (SSID) a network advertises carries a steady stream of management traffic, and that traffic uses airtime whether or not anyone is connected. Apple’s guidance is to run three SSIDs or fewer. Extra names do not add capacity – they quietly subtract it, because the airwaves spend more time on overhead and less on real data. One network for staff, perhaps one for guests, and one more for devices that genuinely need their own is usually enough.

Skip hidden networks

Hiding a network’s name is often treated as a security step, but it is not one: the network is still detectable and the name is trivially recovered. What hiding does do is work against Apple devices specifically. A hidden SSID slows how quickly a device associates with the network, weakens roaming, and increases battery drain, because the device has to actively probe for the name rather than simply hearing it announced. Leave networks visible and rely on a strong password and modern encryption instead. For why a hidden name offers no protection, see SSID and BSSID explained.

Choose bands deliberately

Apple devices use both the 2.4 GHz and 5 GHz bands, and in a busy space 5 GHz is usually the better foundation. It offers many more non-overlapping channels, so neighbouring access points can be configured without competing, and its shorter range is actually an advantage indoors: the signal fades between rooms, which stops one area from interfering with the next. The 2.4 GHz band reaches farther and through more walls, but it has only three non-overlapping channels (1, 6, and 11) and is crowded with other devices. Use 2.4 GHz for reach and older equipment, but build dense areas – classrooms, open-plan offices – around 5 GHz. How channels and bands behave is covered in WiFi channels explained.

Design around how Apple devices roam

This is the part most networks get wrong. An Apple device does not wait until it loses signal to look for a better access point – it starts scanning at a set threshold. A Mac begins looking for a stronger access point at roughly -75 dBm, while iPhone and iPad start at around -70 dBm. The practical consequence: by the time a device reaches those levels, a stronger access point must already be within range, or there is nothing better to move to and the connection degrades. Plan coverage so that signal overlaps – every area should be reached by a second access point well before the first fades past the roaming threshold.

Plan for capacity, not just coverage

A single enterprise access point can serve fifty or more clients, but throughput per device falls as the count climbs. Coverage answers “can a device hear the network here”; capacity answers “can it actually work here when the room is full”. Estimate how many devices will be active in each area – a classroom or meeting room is far denser than a corridor – and add access points where the count is high, not only where the signal is weak. People matter too: bodies absorb radio energy, so a room that tested well empty can struggle once it fills.

Keep access points consistent

Roaming is smoothest when every access point offers the same capabilities and the same configuration: the same encryption, the same band settings, the same network names. A device crossing between mismatched access points may hesitate or refuse to roam at all. Where Apple services such as AirPlay, AirPrint, or Classroom are in use, make sure Bonjour traffic is allowed to pass across the network, since those features rely on it to discover devices.

Validate with a site survey

A design on paper is only a starting point; the real test is walking the space. Survey it both before and after installation:

  1. Open the WiFi Analyzer in IP Tools (Android) or WiFi Tools (iOS).
  2. Walk each area and read the signal in dBm, confirming that coverage stays above the roaming thresholds (-70 dBm for iPhone and iPad, -75 dBm for Mac) wherever devices are used.
  3. Check the channel graph for overlap, and confirm you are not running more SSIDs than you need.

Repeat the survey once the space is occupied, because the people in it change the result. For reading signal strength and channels, see WiFi channels explained and the WiFi Analyzer help page.

FAQ

How many SSIDs should I run for Apple devices?
Three or fewer. Each extra network name adds management overhead that consumes airtime, so additional SSIDs reduce capacity rather than add it.

At what signal level do Apple devices roam?
A Mac starts looking for a better access point around -75 dBm, and iPhone and iPad around -70 dBm. Coverage should overlap so that a stronger access point is available before a device reaches those levels.

Should I hide my SSID for Apple devices?
No. A hidden SSID gives no real security and specifically slows association, weakens roaming, and increases battery use on Apple devices.

Is 5 GHz or 2.4 GHz better for Apple devices?
In dense spaces, 5 GHz is usually better: it has more non-overlapping channels and shorter range, which reduces interference between areas. The 2.4 GHz band reaches farther but offers only three non-overlapping channels and is more congested.

How to Optimise Wi-Fi for a Fleet of Android Devices

A fleet of Android devices – phones for staff, tablets on a shop floor, handheld scanners in a warehouse – puts a different kind of load on Wi-Fi than a handful of personal gadgets. The devices move constantly, they come from many manufacturers, and unlike Apple’s hardware they do not all follow one published set of rules. That fragmentation is the central fact to design around. The plan below covers what actually carries across Android vendors and versions: the roaming standards to turn on, how to plan coverage when you cannot rely on a fixed threshold, how authentication and MAC randomization affect a managed fleet, and how to check the result on site. It is a companion to the same exercise for Apple hardware in optimise Wi-Fi for Apple devices.

Design to standards, not to a single device

Apple publishes the exact signal levels at which iPhones, iPads, and Macs start looking for a better access point. Android has no equivalent. Roaming behaviour differs between Samsung, Pixel, Xiaomi, and the rest, and it shifts between Android versions, so there is no one number to design to. The reliable approach is to lean on the open roaming standards that modern Android devices understand, and to make sure every device always has a clearly stronger access point to move to. You are designing for a moving target, so you build margin into the coverage rather than trusting any single device to behave.

Turn on the roaming standards (802.11k / v / r)

Three IEEE standards make roaming faster and smarter, and Android has supported them for years. Enable all three on your controller or access points, and keep the setting identical across every unit:

  • 802.11k (neighbour reports): the network hands a device a short list of nearby access points and their channels, so it does not have to scan the whole spectrum to find the next one.
  • 802.11v (BSS transition management): the network can actively suggest that a device move to a better access point, instead of waiting for the device to decide on its own.
  • 802.11r (fast transition): the device re-authenticates to the next access point in a fraction of the usual time. This matters most on secured enterprise networks, where a full re-authentication on every hop would otherwise interrupt a call or a barcode scan.

A small number of older clients handle 802.11r poorly, so test the fleet after enabling it rather than assuming every device is happy.

Plan coverage with real overlap

Because you cannot count on a uniform roaming threshold, the design has to do the work the device firmware will not: make the next access point obviously better long before the current one fades. Aim for overlapping cells, where a second access point already delivers a strong signal at the edge of the first. Signal is measured in dBm, a negative scale where closer to zero is stronger: around -30 dBm sitting next to an access point, roughly -67 dBm as a common rule of thumb for reliable voice and video on the move, and -80 dBm and below where connections stall and drop. Plan so that working areas stay comfortably above that rule-of-thumb level and a neighbouring access point reaches the same spot at a similar strength. A plan on paper is only a hypothesis until you walk the space and measure it.

Choose bands and let devices spread out

Android devices use 2.4 GHz, 5 GHz, and – on newer hardware running Android 12 or later – 6 GHz (Wi-Fi 6E). The 2.4 GHz band reaches farther and through more walls but offers only three non-overlapping channels (1, 6, and 11) and is crowded with other devices. The 5 GHz band has many more non-overlapping channels and shorter range, which is an advantage indoors because it limits how much one area interferes with the next; build dense, busy areas on it. The 6 GHz band adds a large block of clean spectrum for the newest devices. Band steering, where the access point nudges a dual-band device onto the less congested band, helps spread a mixed fleet across the available capacity. How channels and bands behave is covered in WiFi channels explained.

Keep the number of SSIDs small

Every Wi-Fi name (SSID) the network advertises carries a steady stream of management traffic that uses airtime whether or not anyone is connected. Extra names do not add capacity – they quietly subtract it. Keep the count low: one network for managed devices, one for guests, and a separate one only for equipment that genuinely needs its own. For why a hidden name is not a security measure, see SSID and BSSID explained; for separating visitors from the fleet, see how to set up a guest Wi-Fi network.

Authenticate the fleet without a shared password

For more than a handful of devices, WPA2 or WPA3-Enterprise (802.1X) is worth the setup. Instead of one Wi-Fi password that every device shares – and that you must change on every device when someone leaves or it leaks – each device gets its own identity or certificate, pushed and revoked centrally through your MDM (mobile device management). Access can then be removed one device at a time without touching the rest. If you do use a shared key (WPA2/WPA3-Personal), remember the trade-off: rotating that key means re-pushing it to the whole fleet, and every device has to reconnect before it works again.

Account for MAC randomization

Since Android 10, a device presents a randomized Wi-Fi address (MAC) to each network by default, and depending on settings that address can change over time. For a fleet this quietly breaks two common practices: MAC-based allowlists stop matching, and DHCP reservations keyed to a hardware address hand out the wrong lease or a brand-new one. There are two clean ways to handle it. Configure the devices through MDM to use their real (device) MAC on your managed network, or stop identifying devices by MAC at all and rely on 802.1X identity instead. Decide before you deploy, not after the address list quietly stops working.

Keep devices on Wi-Fi when you want them there

Many Android phones will fall back to mobile data when Wi-Fi looks poor – a behaviour variously called “switch to mobile data automatically” or adaptive connectivity. On a personal phone that is helpful; on a fleet it can mean devices burning cellular data or leaving your managed network in the middle of a task. If the fleet is meant to stay on Wi-Fi, the real fix is the coverage that triggers the fallback in the first place, and where the platform supports it, the policy can be set through MDM.

Keep access points consistent

Roaming is smoothest when every access point offers the same capabilities and configuration: the same encryption, the same band settings, the same network names, the same roaming standards. A device crossing between mismatched access points may hesitate or refuse to move at all – which undoes the rest of the design.

Validate with a site survey

A design is only a starting point; the real test is walking the space, ideally with the actual fleet devices in hand:

  1. Open the WiFi Analyzer in IP Tools (Android) or WiFi Tools (iOS).
  2. Walk each area and read the signal in dBm, confirming not just that the nearest access point is strong but that a second one already reaches the same working areas – that overlap is what makes roaming work.
  3. Check the channel graph for overlap, and confirm you are not advertising more SSIDs than you need.

Repeat the survey once the space is occupied and devices are active, because people and traffic change the result. For reading signal strength and channels, see WiFi channels explained and the WiFi Analyzer help page.

FAQ

Do Android devices roam at a fixed signal level like Apple?
No. Roaming behaviour varies by manufacturer and Android version, so there is no single threshold to design to. Lean on the 802.11k/v/r roaming standards and on overlapping coverage that always offers a clearly stronger access point.

What is the best way to authenticate a fleet of Android devices?
WPA2 or WPA3-Enterprise (802.1X) with per-device credentials or certificates pushed through MDM. Access can be revoked one device at a time, with no shared password to change across the fleet.

Why do DHCP reservations or MAC allowlists stop working on Android?
Since Android 10, devices use a randomized MAC per network by default. Either configure the real device MAC through MDM on your managed network, or identify devices by their 802.1X identity instead of their hardware address.

Should I enable 802.11r fast transition?
Yes on secured networks – it shortens re-authentication when a device moves between access points, which keeps calls and scans from dropping. Test any very old clients first, as a few mishandle it.

Essential Network Utilities for 2026: The Tools Worth Having

Home and office networks keep getting busier – more smart devices, more Wi-Fi, more that can quietly go wrong. The good news is that diagnosing most of it no longer takes specialist gear; a handful of utilities on your phone covers nearly everything. Here are the network tools worth having in 2026, grouped by the problem each one solves – and, conveniently, they come bundled rather than as a dozen separate apps.

See and fix your Wi-Fi

The first group is about the wireless signal itself. A Wi-Fi analyser shows the networks around you, the channel each one uses, and your signal strength in dBm, so a congested channel or a weak spot is easy to see and act on. This is the tool to reach for when Wi-Fi is slow or drops in certain rooms. For how to use it in practice, see WiFi channels explained and how to speed up home Wi-Fi.

Find every device on your network

A network scanner lists the devices connected to your network, so you can see exactly what is on it – your own gear, and anything that should not be there. It is the basis for checking who is using your Wi-Fi, and even for spotting an unexpected camera in a rental. See who is connected to your Wi-Fi and how to check for hidden cameras.

Test connections and find where delays come from

When something will not load, two tools tell you why. Ping measures whether a destination responds and how quickly, which is how you check reachability and latency. Traceroute goes further and shows each step along the route, so you can see where a delay or failure actually happens – inside your home or out at the provider. Together they separate “my connection is down” from “that one site is down”. They are also the responsiveness half of a speed check, covered in how to check your internet speed.

Resolve names and addresses

This group answers “what is the address, and whose is it”. A DNS lookup turns a site name into the IP address behind it, which is invaluable when a site loads for everyone but you – see how DNS works. IP Info shows your own device’s addressing at a glance, and an IP calculator works out network ranges from an address and mask. If those terms are unfamiliar, what is an IP address, subnet mask, and gateway and how to find your IP address explain them.

Inspect and manage your own devices

The last group is for working with specific devices on your own network. A port scanner checks which ports are open on a device you control, which helps confirm a service is running or that nothing unexpected is exposed. WHOIS looks up the registered owner of a domain or IP address. And Wake-on-LAN powers on a compatible computer over the network, so you can reach it without walking over to press the button. As with all network tools, use these only on equipment you own or are authorised to manage.

One toolkit instead of a dozen apps

The practical lesson of 2026 is to stop chasing a separate app for each job. The tools above all live together in IP Tools (Android) and WiFi Tools (Android and iOS), so the analyser, scanner, ping, traceroute, DNS lookup, and the rest are a tap apart rather than scattered across your home screen. For raw download and upload figures, add a browser-based speed test; for everything diagnostic, the bundled toolkit covers it. Each tool also has its own help page – for example the WiFi Analyzer help page – explaining what every field means.

FAQ

What network tools do I actually need?
For most people, three: a Wi-Fi analyser, a network scanner, and ping. Those diagnose the majority of home network problems. Traceroute, DNS lookup, and the addressing tools cover the rest.

Do I need a separate app for each tool?
No. Bundled toolkits like IP Tools and WiFi Tools include the analyser, scanner, ping, traceroute, DNS lookup, port scanner, WHOIS, and Wake-on-LAN together, so you do not need a different app for each.

Can these tools test my internet speed?
They measure the responsiveness side – ping and latency – directly. For raw download and upload throughput, use a browser-based speed test alongside them; see how to check your internet speed.

Advanced Router Settings for a Small Business

Once the basics are in place – a network name, a strong password, the firmware up to date – a small business usually runs into a handful of settings that the home-user guide never needed. Reaching a server from outside, keeping a printer at the same address, prioritising a video call over a backup upload: each is a specific setting with a specific purpose, and each carries a trade-off worth understanding before you turn it on. This is a practical tour of the advanced settings a small office actually uses, what each one does, when you need it, and how to change it without locking yourself out or opening a door you did not mean to. It picks up where how to set up your router from your phone leaves off, and assumes a router you own.

Port forwarding

By default a router blocks connections that start from the internet, which is exactly what you want – it means nothing outside can reach the devices inside. Port forwarding deliberately opens one specific door: it maps an external port to a particular internal device and port, so that, say, a connection to your public address on a chosen port is handed to a server inside. You use it to reach something from outside: a server, a camera recorder, a remote-access service. The caution is the whole point. Every forward is an opening, so forward only what you genuinely need, send it to a fixed internal address, and verify afterwards from the internet side that only the intended port is reachable – a scan of your own public address confirms this, as covered in how to read a port scan of your own devices. Where you would otherwise forward several ports for remote access, a VPN into the network is usually the safer choice, exposing one well-guarded entry instead of many.

Fixed internal addresses

Anything you forward to, or rely on at a steady location – a server, a printer, a recorder – needs an address that does not change. Left to itself, the router hands out addresses dynamically and a device may get a different one after a reboot, which quietly breaks a forward or a saved connection. The clean fix is a DHCP reservation: you tell the router to always give a particular device the same address, keyed to its hardware address (MAC). It is better than configuring a fixed address by hand on the device, because the router stays the single source of truth and there are no clashes. Note that phones and laptops using randomized MAC addresses complicate reservations; servers and fixed equipment use their real address, so they reserve cleanly.

Dynamic DNS

Most consumer and many business-grade internet connections get a public address that can change without warning. That is a problem the moment you depend on reaching your network from outside, because the address you forwarded to yesterday may be someone else’s today. Dynamic DNS (DDNS) solves it: a small client – on the router or a device inside – tells a DDNS provider whenever the public address changes, and keeps a fixed hostname pointed at it. You then reach the network by name instead of by an address you would otherwise have to look up constantly. It is what makes port forwarding and remote access practical on a connection without a static address.

Static routes

Most small networks never need a static route, and it is worth knowing why before you add one. A router already knows how to reach the networks directly attached to it and how to send everything else toward the internet. A static route is an explicit instruction for a case it cannot infer on its own: traffic for a particular network must be sent via a particular gateway – for example, a second subnet behind another router, or a separate segment reached through a specific device. If you have segmented your network, this is where the segments are taught how to reach one another deliberately; the broader picture is in network segmentation with guest and IoT VLANs. If you have a single flat network, you almost certainly do not need to touch this.

Quality of Service (QoS)

When one big upload can make a video call stutter, the cause is usually contention: everything shares the same connection, and a bulk transfer happily consumes all of it. Quality of Service lets the router prioritise some traffic over the rest, so that latency-sensitive things – calls, video, anything real-time – get served ahead of a backup or a large download that will not notice a brief wait. This matters because real-time media cannot recover a late packet, so protecting its timing is what keeps a call clear; the reasoning is in TCP vs UDP. Keep the rules simple: prioritise the few things that genuinely suffer under load, rather than trying to rank everything.

Firewall rules

The router’s firewall is what enforces “blocked by default, allowed by exception”. The inbound default should stay deny – nothing from outside reaches in unless a forward or rule explicitly permits it. On a segmented network the same discipline applies between segments: allow only the traffic that genuinely needs to cross, and deny the rest, so a guest or device segment cannot freely reach the trusted one. Each rule you add is something to account for later, so keep the set small and write down why each one exists.

Change it safely

Advanced settings are also the ones that can lock you out or quietly expose something, so the method matters as much as the setting:

  • Change one thing at a time and test it before the next, so a problem has an obvious cause.
  • Write down what you changed and why – the rule whose purpose nobody remembers is the one that becomes a risk.
  • Keep firmware current; these features and their security fixes arrive in updates.
  • Verify exposure from the outside. After any forward, scan your own public address to confirm only the intended port answers and nothing else slipped open.

Where the app fits

The settings themselves live in the router’s own admin interface, not in a phone app – but a phone is useful for getting there and for checking your work. The Router Setup tool in IP Tools (Android) or WiFi Tools (iOS) helps you find the router’s address and open its admin page, and IP Info shows your gateway and public address, which you need when setting up forwarding or DDNS. After you make a change, the Port Scanner lets you confirm from outside that only the ports you intended are reachable. Reading the router’s address is covered on the Router Setup help page, and your current addresses on the IP Info help page.

FAQ

What is port forwarding used for?
It opens a specific external port and directs connections to a chosen internal device, so you can reach something inside the network from the internet – a server, a recorder, a remote-access service. Forward only what you need and verify afterwards that nothing else is exposed.

Why do I need dynamic DNS?
Because most connections have a public address that changes. Dynamic DNS keeps a fixed hostname pointed at your current address, so remote access and port forwarding keep working without you tracking the address by hand.

Do I need static routes on a small network?
Usually not. A single flat network does not need them. You add a static route only when traffic for a particular network must go via a specific gateway, such as a second subnet or a separate segment behind another device.

What does QoS actually do?
It tells the router to prioritise latency-sensitive traffic – calls and video – over bulk transfers, so a large upload or download does not make a real-time call stutter. Keep the rules to the few things that genuinely suffer under load.