This is the order of operations we use when improving a home or small-business network people already depend on — not a dump of vendor SKUs.
1. Name the zones
Before touching hardware, decide who talks to whom: trusted phones and laptops, wired lab/servers, IoT, work devices, guests. Isolation is a policy decision first. The VLAN numbers come second.
2. Put routing on dedicated hardware
Consumer “router as everything” boxes make segmentation painful. A small OpenWrt box as router/firewall, with access points doing Wi‑Fi only, keeps roles clear. Harden admin access early.
3. Filter DNS in the path
Ad and tracker blocking belongs in the network, not as an app everyone forgets to install. Persist the config so a reboot doesn’t wipe filters. Force DNS so devices can’t casually walk around the filter.
4. Build a human control surface
Parental controls fail when they require logging into a router UI. Group devices (consoles, phones, streaming sticks) and expose block/allow as one tap per group — plus schedules for school nights. Manual override matters more than perfect automation.
5. Document the switch day
Trunk ports, AP mode, SSID-to-VLAN mapping, and a test checklist. Downtime is short when the checklist exists before the cables move.
Related
The project page tells the story. This guide is the pattern you can reuse for a household or a small shop.