To clarify my note,
- set router LAN static IP (192.168.1.1) and DHCP server IP Pool of dynamic and manually-assigned IPs (192.168.1.10-254 leaves static IPs .1-9 for non-DHCP use)
The choice of IP range is yours... 192.168.1.* is commonly used/understood and used here for example... and perhaps it is more easily assumed and exploited(?).
Router DHCP server-assigned IPs within its IP Pool are termed dynamic and manually-assigned IPs.
User-assigned IPs assigned manually on the client from outside of the DHCP server IP Pool are termed static IPs.
OE
Yeah, I figured the suggestion was just a guideline. I followed your outline though because I wanted the traditional local ip range. I'm used to 192.168.1.x for non Apple routers. For the Airport it's typically 10.0.1.x. The starting at 192.168.10 for the DHCP assigned IP range, also made sense for my setup, because whenever I do assign manual IPS, I typically start with .2, .3, etc to make it easy to remember linear assignments, so it made sense to exclude those so they could manually be used without running into conflicts, if the DHCP server were to assign one of those IPs. As far as other parts of your notes I applied were turning off smart connect, and using separate SSIDs, which is also good for my setup as I have devices that need to stay on a specific band, and if I need to pair a new device, makes it much easier to manually connect to 2.4Ghz with the phone to do the setup and switch back to 5Ghz once the device is set up and configured.
Regarding your suggestions on SIP Passthrough, I left it enabled, I don't have a VOIP service, but I will occasionally use software such as Skype, or Apple's FaceTime, etc but I don't think those apply here.
I disabled all 3 sources of UPNP found in the AsusWRT settings under WAN, the G-Force NOW setting, and the UPNP setting for the media server in usb applications. If I need to open a port, I'll do a manual port forward. I had been using UPNP for remote access to Plex, and a software package called SERVIIO Media Server, as I had given Alexa access to play my content, but since I haven't used those skills in a couple years. I decided to just disable them, and disable remote access as to not leave unused ports open.
So, I think that's a brief up to date summary of the changes I've made to the router and network, based on your guidelines and suggestions.
I also made sure remote access for WAN and DDNS are disabled too.