Should I restart a router?¶
A router should not normally be restarted as an immediate first-response action unless a specific operational need justifies the evidential loss.
Avoid this assumption: Restarting is a harmless troubleshooting step. A restart may clear volatile logs, connection tables, active sessions, temporary configuration and security alerts.
It may also interrupt internet access, telephony, alarms, cameras, servers, payment systems or other services that depend on the router.
Before considering a restart, record the device, status lights, display, connected cables, warnings, uptime and any open management interface.
Identify the problem you are trying to solve. Is there an active safety risk, serious ongoing harm or critical service failure?
Do not restart merely because the network is slow, inaccessible or suspected of compromise.
Where a cyber incident is active, a restart may stop some malicious activity but also remove visibility of the attacker and destroy useful live evidence.
Seek network, system-administration or incident-response advice before acting.
If urgent operational necessity requires restart, record who authorised it, the exact time, the reason and the services expected to be affected.
Capture the state immediately before and after the restart.
Record any loss of logs, changed IP addresses, renewed connections, altered alerts or service failures.
Do not describe the restarted system as being in its original state.
Record whether a restart is being proposed for evidence preservation, service recovery, user convenience or containment, because those are different decisions with different thresholds.
Operational takeaway¶
Restart a router only where a defined operational need outweighs the loss of volatile evidence and service continuity, and document the full before-and-after state.