ONE STEP AT A TIME
Let’s get you
protected.
You don’t need to be a networking expert. Connect your Shield, keep its address the same, then tell your network to use it.
Guides for 10 router families—not a market-share ranking. Based on manufacturer instructions checked September 20, 2026. Menus vary by model, app version and internet provider; not every model has been hardware-tested.
STEP 01
Connect the Shield
- Power it on. Follow the supplied connection card for your hardware. For the Wi-Fi setup version, join the temporary setup Wi-Fi named on the device/card. Stay connected if your phone says “No internet.”
- Open its setup page. If it does not appear automatically, enter
http://192.168.4.1into your browser’s address bar while connected to setup Wi-Fi. This is only the temporary setup address—not the address to enter in your router’s DNS settings. - Choose your home Wi-Fi. Select its name (the field may say “SSID”), enter its password and follow the connection prompt. Choose a band supported by your device. Wait for the page to confirm the connection; do not unplug during setup or an update.
- Save the three setup details. On the router-setup screen, select “Copy setup details” or take a screenshot: Privacy address (your Shield’s home-network IP), Privacy MAC (its network identifier), and Router address. Some firmware still uses the shorter name “Privacy.”
- Select “Continue on home Wi-Fi.” The setup network closes and the device restarts. The small setup window may close too; that is normal. Reconnect your phone to your usual home Wi-Fi, open a regular browser, and return to this guide.
- Open your Shield’s home-network address. Enter
http://followed by the saved Privacy address. On the Privacy page, find “Firmware and protection-list updates,” enter your “Subscription activation code,” and choose “Activate updates.” Wait for confirmation. Never enter that code into your router.
Already connected by Ethernet? Use the address and MAC for the connected Ethernet interface from the device page or router’s connected-device list. Do not reserve the Wi-Fi MAC for an Ethernet connection. If your hardware has a different onboarding screen, follow its supplied card first.
Three terms, in plain English
- IP address
- A device’s address inside your home. Use the actual address shown by your Shield, not an example from a guide.
- DHCP reservation
- Your router promises to give the Shield the same address every time. Also called Address Reservation, Reserved IP or Static Lease.
- DNS
- The lookup service devices ask where websites are. Point this to your Shield so it can filter supported lookups.
Keep automatic addressing on the Shield. Reserve its current address in the router instead of guessing a new static address. That avoids conflicting with another device.
STEP 02
Choose your router
Look for the brand and model on the router’s label or in its app. If you have a separate mesh system, use the router that assigns addresses to your home devices. An access point or extender may not control DNS or DHCP.
For every router: reserve the Shield’s current home-network address first. Then use that address as Primary DNS. Leave Secondary DNS empty if allowed; use the same Shield address only if the router accepts it. A public secondary DNS can bypass filtering—it is not reliably “backup only.” If a second, different address is required, stop and get model-specific help. Never invent one.
TP-Link Archer Router web page
- While on home Wi-Fi, open the saved Router address and log in.
- Open Advanced → Network → DHCP Server → Address Reservation. Add the Shield’s MAC and current IP; enable the entry and save.
- In DHCP Server, set Primary DNS to the Shield’s IP and save. Keep DHCP enabled and leave the gateway and pool unchanged.
- Reconnect one phone or computer to Wi-Fi, then follow Step 3 below.
Older interfaces may call this DHCP Settings. Prefer the LAN/DHCP DNS field for a local Shield, not an Internet/WAN field that rejects local addresses.
Official help: Address reservation · DHCP DNS menu
TP-Link Deco Deco app
- Open More → Advanced → Address Reservation, tap + and select the Shield from connected clients. Save its current IP.
- Go to More → Advanced → DHCP Server. Enter the Shield’s IP as Primary DNS and save.
- Reconnect a test device and check protection below.
This is for Deco in router mode. In access-point mode, make DHCP/DNS changes on the upstream router instead. Do not switch modes just to expose a menu.
Official help: Reserve an address · Change DNS
ASUS / ZenWiFi ASUSWRT web page
- Log in at your saved Router address. Open LAN → DHCP Server.
- Enable manual assignment. Select the Shield’s MAC, keep its current IP, add the entry and apply.
- Under the DNS server settings on the same page, enter the Shield’s IP. If offered, turn off advertising the router’s IP in addition to the user-specified DNS. Apply.
- Reconnect a test device and check protection below.
Keep the DHCP server enabled. Mesh satellites in access-point mode do not control the main network’s DHCP.
Official help: DHCP and DNS settings · Manual address assignment
NETGEAR / Nighthawk Router web page
- Log in at the Router address. Open ADVANCED → Setup → LAN Setup.
- Under Address Reservation, add the Shield’s current IP and MAC; apply.
- Open BASIC → Internet. Under Domain Name Server (DNS) Address, choose manual DNS and enter the Shield’s IP. Apply without changing the Internet IP or connection type.
- Reconnect a test device and check protection below.
This path changes router/upstream DNS. The Shield may see requests grouped under the router rather than each device. If your model rejects a local DNS address, stop; use its model-specific manual.
Official help: Reservation · DNS
Linksys / Velop Web page + mesh app
- For the dual-band web interface, open Configuration → Connectivity → Local Network → DHCP Reservation. Select the Shield, add it and save its current address.
- For mesh DNS in the Linksys app, open Advanced Settings → Local Network Settings. Put the reserved Shield IP in Static DNS 1 and save.
- Reconnect a test device and check protection below.
These are separate interface families. LinksysNOW uses Menu → Advanced Settings → Local Network → DHCP Server → DHCP Reservations. If yours differs, use the matching official instructions; do not change WAN to Static IP.
Official help: Dual-band reservation · LinksysNOW reservation · Mesh DNS
Amazon eero eero app
- In Settings, open the network/advanced networking settings, then Reservations & port forwarding → Add a reservation. Select the Shield and save its current IP. Do not add a port-forwarding rule.
- Open DNS → Custom DNS in network settings. Set IPv4 Primary DNS to the Shield’s address and save; follow any restart prompt.
- Reconnect a test device and check protection below.
eero Plus filtering can prevent custom DNS. Review eero’s instructions before disabling its security/content filters: doing so removes those protections. Local DNS caching and HomeKit can make requests appear to come from the eero.
Official help: Reservation section only · Custom DNS and feature conflicts
Google / Nest Wifi Google Home app
- Open Home → Wifi → Network settings → Advanced Networking → DHCP IP reservations.
- Add a reservation, choose the Shield, enter its current address and save.
- Back in Advanced Networking → DNS, choose Custom. Enter the Shield’s address for IPv4 Primary and save.
- Reconnect a test device and check protection below.
Do not put an IPv4 address into an IPv6 box. Review the IPv6 note below before assuming every device is covered. Keep mobile data available in case you need to restore DNS in the app.
Official help: IP reservations · Custom DNS
Ubiquiti UniFi UniFi Network
- Open Client Devices, select the Shield, then its settings. Enable Fixed IP Address, retain its current address and save.
- Go to Settings → Networks, select the home network, and find DHCP service/DNS settings. Set the DHCP DNS server manually to the Shield’s address and save.
- Reconnect a test device on that network and check protection below.
Requires a gateway/DHCP server you manage; UniFi access points alone cannot do this. Separate guest/IoT networks may not be allowed to reach the Shield. Ask the administrator rather than opening broad firewall access.
Official help: Fixed IP and local DNS · DHCP settings
FRITZ!Box FRITZ!OS web page
- Open the Router address and log in. Under Home Network → Network → Network Connections, edit the Shield and select the option to always assign it the same IPv4 address. Save.
- Under Home Network → Network → Network Settings → IPv4 Settings, set Local DNS server to the Shield’s address and apply. Some versions first require showing additional settings.
- Reconnect a test device and check protection below.
Use the local DNS setting for home-network devices, not the provider’s Internet DNS fields. IPv6 has a separate setting; do not guess an IPv6 address.
Official help: Same IP assignment · Local DNS configuration
GL.iNet Firmware 4 web panel
- Log in at the Router address. Open Network → LAN → Address Reservation. Add the Shield’s MAC and current IP, then apply.
- In Network → LAN → DHCP Server → Advanced, use the DNS server field, where available, to advertise the Shield’s IP to clients. Apply.
- If that field is absent, consult the DNS guide for your exact firmware before using Network → DNS → Manual DNS.
- Reconnect a test device and check protection below.
VPN DNS, encrypted DNS and built-in AdGuard Home can change which resolver is used. Do not assume they combine automatically with the Shield.
Official help: LAN, DHCP and reservations · DNS options
STEP 03
Check that it worked
- Reconnect one test device. Turn its Wi-Fi off and on while staying on the main home network. If it still keeps old settings, restart that device. TVs may need a full restart.
- Check normal browsing. Open a few websites or an app. Open the Shield’s saved home-network address in another tab.
- Check fresh DNS activity on the Privacy page. Look for activity that increases as you use the test device. Router-proxied DNS may appear under the router instead of the individual device. A green light, an activated subscription or a working website alone does not prove DNS is passing through the Shield.
- Repeat with the TV and other devices. Reconnect or restart them so they pick up the new settings. No blocked requests yet can simply mean no listed domain has been requested.
Activity is missing, or some devices bypass protection
Confirm the Shield is powered, its reserved IP matches the DNS entry, and both devices are on the same reachable network. Guest isolation, VPNs, browser Secure DNS, Android Private DNS, Apple Private Relay and hard-coded DNS can bypass local filtering. Temporarily test without an optional VPN/encrypted-DNS feature only if you understand the privacy tradeoff; restore it afterward.
IPv6 is separate. Changing IPv4 DNS does not automatically change DNS advertised over IPv6. Do not enter the IPv4 address in an IPv6 field or switch off IPv6 blindly. Get instructions for your exact router and firmware if activity is still bypassing the Shield.
If you changed router/upstream DNS, the Shield must not send its own upstream lookups back to that same router; that would create a loop. Stop and get help if browsing fails after this change. Do not edit the Shield’s advanced settings at random.
The local setup page will not open
For initial setup, join the device’s setup Wi-Fi and type the full http://192.168.4.1 address; do not search for it. After handoff, use your home Wi-Fi and the saved Privacy address instead. Temporarily disconnect a VPN if it blocks local access. If the Shield’s IP changed, find its MAC in the router’s client list. Do not factory-reset the router.
Need to undo the change?
- Keep the Shield powered while restoring DNS. Open the router by its saved numeric Router address, or use its app with mobile data if necessary.
- Restore the exact DNS settings from your photo—or Automatic/ISP DNS if that was the original choice. Save.
- Reconnect or restart affected devices. Confirm normal browsing works before disconnecting the Shield.
A reservation can remain in place. Do not factory-reset either device to undo a DNS change. With the Shield as your only DNS server, unplugging it can prevent new website lookups until you restore DNS.
This guide does not change your router automatically or collect router passwords. DNS filtering is not a complete firewall and cannot block every advertisement or tracking connection. Manufacturer links are reference material, not endorsements.