This is the order of operations we use when improving a home or small-business network people already depend on — not a dump of vendor SKUs.

1. Name the zones

Before touching hardware, decide who talks to whom: trusted phones and laptops, wired lab/servers, IoT, work devices, guests. Isolation is a policy decision first. The VLAN numbers come second.

2. Put routing on dedicated hardware

Consumer “router as everything” boxes make segmentation painful. A small OpenWrt box as router/firewall, with access points doing Wi‑Fi only, keeps roles clear. Harden admin access early.

3. Filter DNS in the path

Ad and tracker blocking belongs in the network, not as an app everyone forgets to install. Persist the config so a reboot doesn’t wipe filters. Force DNS so devices can’t casually walk around the filter.

4. Build a human control surface

Parental controls fail when they require logging into a router UI. Group devices (consoles, phones, streaming sticks) and expose block/allow as one tap per group — plus schedules for school nights. Manual override matters more than perfect automation.

5. Document the switch day

Trunk ports, AP mode, SSID-to-VLAN mapping, and a test checklist. Downtime is short when the checklist exists before the cables move.

Related

The project page tells the story. This guide is the pattern you can reuse for a household or a small shop.