What this page covers
Log types, timestamps, WAN/DHCP/Wi-Fi/security events, redaction, export, false positives and escalation. The exact menu name differs by brand, hardware revision, ISP firmware and region. Use the official source for your device before changing a setting.
Step-by-step checklist
Evidence and interpretation
| Check | What it tells you | What it does not prove |
|---|---|---|
| WAN timeout | Connection or upstream event | Not proof of an attack |
| DHCP conflict | Two devices or a changed network | Not proof that a device is malicious |
| Repeated auth failure | Could be a client, app or attack | Needs model-aware context |
Common mistakes to avoid
- Using a popular IP, firmware file or menu path as if it were universal.
- Copying a password, screenshot or configuration file into a public forum.
- Changing several settings at once, which makes the cause impossible to isolate.
- Assuming a successful local test proves Internet, WAN, security or every-client behavior.
Frequently asked questions
Will this work on every router?
No. Use the exact model manual and firmware context. Router Portal explains the decision process and common patterns, not a universal guarantee.
Do I need to provide my router password?
No. Never enter an admin password, Wi-Fi key or private network screenshot into Router Portal.
Should I factory-reset first?
Usually no. Record evidence and try the least destructive, documented step first.
Sources and limits
manufacturer log manual · CISA security guidance · ISP event documentation. Vendor menus vary by model, hardware revision, region and firmware. Confirm the exact manual or support page before changing a setting.
Related router guides
Editorial note: This page should show an author/reviewer and last-reviewed date in the production template. If a source or model detail changes, update the page rather than preserving an outdated universal claim.