How to Create Your Counter-Strike Source Server
This guide explains how to install and configure a dedicated Counter-Strike Source (CSS) server on your Linux VPS or dedicated server.
Order a Server
To host your Counter-Strike Source server, HostMyServers offers several gaming-optimized options:
- Performance VPS - Ideal for a CSS server (1 vCPU and 2 GB of RAM are enough)
- NVMe VPS - Excellent value for money
- Eco Dedicated Servers - To host several game servers
- Performance Dedicated Servers - Maximum performance
Prerequisites
The resources listed below correspond to the server's needs and do not take into account the resources already used by the operating system, the installed software or the other services present on the machine.
Allow about 10 Mbps for 30 players at tickrate 66 with sv_maxrate 30000, and double that at tickrate 100.
- SSH access as root or user with sudo
- 64-bit Linux system (Debian 12/13 or Ubuntu 22.04/24.04 recommended)
- Active firewall: nftables (recommended), iptables or ufw (use only one firewall tool at a time)
- Minimum 1 GB of RAM (2 GB recommended)
- About 5 GB of free disk space
- Port 27015 UDP accessible (and port 27015 TCP for RCON, from your fixed IP address only)
Required Configuration
| Component | Minimum | Recommended |
|---|---|---|
| RAM | 1 GB | 2 GB |
| CPU | 1 core | 2 cores |
| Storage | 5 GB | 10 GB SSD |
| Network | 100 Mbps | 1 Gbps |
Counter-Strike Source uses port 27015 over UDP for the game and over TCP for RCON access (remote administration), which must be reachable only from your IP addresses (requires a fixed IP address).
System Update
sudo apt update && sudo apt upgrade -y
Installing Dependencies
SteamCMD and the CSS server are 32-bit programs: 32-bit libraries are required. First check that the i386 architecture is enabled:
sudo dpkg --print-foreign-architectures
If the output is empty, run:
sudo dpkg --add-architecture i386
sudo apt update
Then install the required packages:
sudo apt install -y wget tar screen lib32gcc-s1 lib32stdc++6
Creating a Dedicated User
For security reasons, create a dedicated user:
sudo adduser --disabled-password --gecos "" css
Firewall Configuration
Open port 27015 over UDP for players. Port 27015 over TCP is RCON: restrict it to your fixed IP address (replace YOUR_IP).
With UFW
sudo ufw allow 27015/udp
sudo ufw allow from YOUR_IP to any port 27015 proto tcp
sudo ufw reload
With iptables
sudo iptables -A INPUT -p udp --dport 27015 -j ACCEPT
sudo iptables -A INPUT -p tcp -s YOUR_IP --dport 27015 -j ACCEPT
sudo iptables-save | sudo tee /etc/iptables/rules.v4
Saving the rules across reboots requires the iptables-persistent package.
With nftables
These commands use the inet filter table and the input chain, present by default in /etc/nftables.conf on Debian.
sudo nft add rule inet filter input udp dport 27015 accept
sudo nft add rule inet filter input ip saddr YOUR_IP tcp dport 27015 accept
(echo "flush ruleset"; sudo nft list ruleset) | sudo tee /etc/nftables.conf
Never open TCP port 27015 to everyone: it gives access to RCON. Without a fixed IP address, do not open this port and use an SSH tunnel instead.
Installing SteamCMD
Log in as the css user:
sudo -u css bash
cd ~
Create the directories and download SteamCMD:
mkdir -p ~/steamcmd ~/css-server
cd ~/steamcmd
wget https://steamcdn-a.akamaihd.net/client/installer/steamcmd_linux.tar.gz
tar -xzf steamcmd_linux.tar.gz
Downloading the CSS Server
Start the server installation (application ID 232330):
./steamcmd.sh +force_install_dir /home/css/css-server +login anonymous +app_update 232330 validate +quit
If the installation stops with an error, simply run the same command again: SteamCMD resumes where it left off.
When it finishes, the message Success! App '232330' fully installed. is displayed.
Server Configuration
server.cfg File
Create the configuration file:
nano ~/css-server/cstrike/cfg/server.cfg
Basic Configuration
hostname "My CSS Server"
sv_password ""
rcon_password "ChangeMe"
sv_region 3
sv_lan 0
sv_cheats 0
mp_timelimit 30
mp_freezetime 6
mp_friendlyfire 0
mp_autoteambalance 1
mp_limitteams 2
sv_alltalk 0
Custom Advanced Configuration
Example of a more complete configuration, to adapt to your community:
// Server.cfg created by Let's Go
// For the Free 4 Funs community
// Shared for hostmyservers.fr
// Version 1.2
// -------------------------------------------------------------------------------------
// SERVER SETTINGS
// -------------------------------------------------------------------------------------
// -------------------------------------------------------------------------------------
// RCON security and password
// -------------------------------------------------------------------------------------
// RCON password (to be changed)
rcon_password "changeme"
// Password to join the server (public server: leave empty)
sv_password ""
// -------------------------------------------------------------------------------------
// Server identification
// -------------------------------------------------------------------------------------
// Server name
hostname "My CSS Server"
sv_region 3
sv_lan 0
// Ban duration (in minutes) after failed RCON access attempts
sv_rcon_banpenalty 60
// Maximum number of failed RCON access attempts before banning
sv_rcon_maxfailures 10
// Minimum number of failed RCON access attempts before banning
sv_rcon_minfailures 5
// Time window (in seconds) over which failures are counted (see sv_rcon_minfailures)
sv_rcon_minfailuretime 900
// -------------------------------------------------------------------------------------
// Server configuration
// -------------------------------------------------------------------------------------
mp_allowspectators 1
mp_autocrosshair 0
mp_autokick 0
mp_autoteambalance 0
mp_buytime 0.5
mp_c4timer 30
mp_chattime 8
mp_fadetoblack 0
mp_flashlight 1
mp_footsteps 1
mp_forcecamera 0
mp_forcerespawn 0
mp_fraglimit 0
mp_freezetime 4
mp_friendlyfire 1
mp_hostagepenalty 0
mp_limitteams 1
mp_maxrounds 0
mp_playerid 0
mp_roundtime 3
mp_spawnprotectiontime 5
mp_startmoney 16000
mp_timelimit 20
mp_tkpunish 0
mp_weaponstay 1
mp_winlimit 0
sv_accelerate 5
sv_gravity 800
sv_maxspeed 320
sv_pausable 0
sv_timeout 40
// -------------------------------------------------------------------------------------
// Security
// -------------------------------------------------------------------------------------
sv_cheats 0
sv_consistency "1"
sv_pure "2"
sv_pure_kick_clients "1"
// -------------------------------------------------------------------------------------
// Server logs
// -------------------------------------------------------------------------------------
log on
sv_logbans 1
sv_logecho 1
sv_logfile 1
sv_log_onefile 1
sv_logsdir logs
mp_logdetail 3
// -------------------------------------------------------------------------------------
// Server bandwidth
// -------------------------------------------------------------------------------------
// Fast download (FastDL): address of a web server hosting the files
//sv_downloadurl "https://xxxxxxxxxxxxxxxxxxx"
// Allow downloads
sv_allowdownload 1
// Allow file uploads by players (sprays, etc.)
sv_allowupload 1
// Configuration optimized for a tickrate of 100
// Requires the Tickrate Enabler extension for CS:Source and the -tickrate 100 launch parameter
// Unlimited server-side FPS (0 = unlimited, uses more resources)
fps_max 0
// -------------------------------------------------------------------------------------
// Do not change these values if you do not know what you are doing
// sv_maxrate 0: unlimited rate
// sv_maxrate 30000: 30,000 bytes/s (about 0.24 Mbps) per player
// -------------------------------------------------------------------------------------
net_queued_packet_thread 0
sv_mincmdrate 75
sv_maxcmdrate 101
sv_maxrate 0
sv_minrate 20000
sv_maxupdaterate 101
sv_minupdaterate 75
// -------------------------------------------------------------------------------------
// Ban management
// -------------------------------------------------------------------------------------
// Loads the list of players banned by SteamID and by IP address
// (files to be placed in cstrike/cfg)
exec banned_user.cfg
exec banned_ip.cfg
// -------------------------------------------------------------------------------------
// Bot management
// -------------------------------------------------------------------------------------
// To enable bots, remove the // in front of the next line
// (the bot.cfg file must be located in cstrike/cfg)
//exec bot.cfg
// -------------------------------------------------------------------------------------
// Server statistics
// -------------------------------------------------------------------------------------
sv_stats 1
sv_filterban 1
echo ==============================
echo Server.cfg correctement charge
echo ==============================
echo ===============================
echo Visitez wiki.free4funs.ovh
echo Visitez hostmyservers.fr
echo ===============================
echo ===============================
echo Server.cfg Config By Lets'Go
echo ===============================
Choose a long and unique rcon_password. Anyone who knows it can administer your server.
Main Parameters
| Parameter | Description |
|---|---|
hostname | Public name of the server |
sv_password | Password to join (empty = public) |
rcon_password | Remote administration password |
sv_region | Region: 3 = Europe, 0 = US East, 4 = Asia, 255 = worldwide |
sv_lan | 0 = server visible on the Internet, 1 = local network only |
mp_timelimit | Duration of a map in minutes |
mp_freezetime | Freeze time at the start of a round, during which players buy their equipment (seconds) |
mp_friendlyfire | Friendly fire (0 = disabled, 1 = enabled) |
sv_alltalk | Voice chat between the two teams (0 or 1) |
GSLT Token (Optional)
The GSLT (Game Server Login Token) is not mandatory but recommended: it allows your server to be listed among the public Steam servers.
To generate it, log in to your Steam account and go to the Steam Game Server Account Management.
Creating the token has a few prerequisites:
- Your Steam account must not be community banned or locked
- Your Steam account must not be limited
- Your Steam account must have a phone number registered
- Your Steam account must own the game for which you are creating a game server account
- Your Steam account can create up to 1000 game server accounts
In the App ID of the base game field, enter 240. You can add a memo to remind yourself which server it is for, then finish by clicking the Create button.
To use the token, add it to the launch line:
+sv_setsteamaccount YOUR_TOKEN
Add the parameter to all your launch lines: the first launch, the ExecStart line of the systemd service and the command launched with screen.
First Launch
cd ~/css-server
./srcds_run -game cstrike -console +map de_dust2 +maxplayers 24 -port 27015
Once startup is complete, the console displays the status of the connection to the Steam servers. To stop the server, type quit.
Launch Optimization
Launch Parameters
| Parameter | Description |
|---|---|
-game cstrike | Game to launch (mandatory) |
+map | Starting map |
+maxplayers | Maximum number of players (up to 64) |
-port | Server port (27015 by default) |
-ip | IP address to listen on |
-tickrate 100 | Simulation frequency (66 by default). Increases CPU load and requires the Tickrate Enabler extension |
-norestart | Prevents the script from restarting the server if it stops (useful with systemd) |
-console | Runs in console mode |
-debuglog file_name | Writes the debug output to the file |
-high | Maximum priority for the server process |
-nohltv | Disables SourceTV |
-nobots | Disables bots |
-insecure | Disables VAC protection (see the warning below) |
+sv_setsteamaccount | GSLT token (optional, see the dedicated section) |
-insecure disables VAC protection: only use this parameter for testing, as it leaves the door open to cheaters.
Changing the Port
./srcds_run -game cstrike -console +map de_dust2 +maxplayers 24 -port 27016
Don't forget to open the new port in the firewall.
File Structure
| Path | Description |
|---|---|
cstrike/cfg/ | Configuration files |
cstrike/cfg/server.cfg | Main configuration |
cstrike/cfg/banned_user.cfg | Banned players (SteamID) |
cstrike/cfg/banned_ip.cfg | Banned IP addresses |
cstrike/maps/ | Installed maps |
cstrike/addons/ | Extensions (Metamod, SourceMod) |
cstrike/logs/ | Log files |
Configuration as systemd Service
Create Service File
Exit the css user's session (exit) to return to your administrator account, then create the service file:
sudo nano /etc/systemd/system/css.service
File content:
[Unit]
Description=Counter-Strike Source Server
After=network.target
[Service]
Type=simple
User=css
Group=css
WorkingDirectory=/home/css/css-server
Environment=TERM=xterm
ExecStart=/home/css/css-server/srcds_run -game cstrike -console -norestart +map de_dust2 +maxplayers 24 -port 27015
Restart=on-failure
RestartSec=20
[Install]
WantedBy=multi-user.target
Enable and Start Service
sudo systemctl daemon-reload
sudo systemctl enable css.service
sudo systemctl start css.service
Management Commands
# Check status
sudo systemctl status css.service
# Stop server
sudo systemctl stop css.service
# Restart server
sudo systemctl restart css.service
# View logs
sudo journalctl -u css.service -f
With systemd, the server console is not interactive. To send commands, use RCON from the game or launch the server with screen (see below).
Launching with screen (Alternative)
If the systemd service is started, stop it first (sudo systemctl stop css.service): two servers cannot use the same port.
sudo -u css bash
cd ~/css-server
screen -S css
./srcds_run -game cstrike -console +map de_dust2 +maxplayers 24 -port 27015
To detach: Ctrl+A then D
To reattach: screen -r css
Launching in the Background with a Log
sudo -u css bash
cd ~/css-server
screen -AdmSL css ./srcds_run -game cstrike -console +map de_dust2 +maxplayers 24 -port 27015
| Option | Description |
|---|---|
-A | Adapts the window to the terminal size |
-d -m | Starts the session detached, in the background |
-S css | Session name |
-L | Writes the server output to a log file |
The screenlog.0 file is created in the folder where the command is run (~/css-server) and contains all the server-side output. To follow it live:
tail -f ~/css-server/screenlog.0
In case of a startup error, this is the first file to check. To return to the server console: screen -r css
The screenlog.0 file grows with each launch. Remember to purge or delete it regularly.
Server Update
Stop Server
sudo systemctl stop css.service
Download the New Version
sudo -u css bash
cd ~/steamcmd
./steamcmd.sh +force_install_dir /home/css/css-server +login anonymous +app_update 232330 validate +quit
exit
Restart Server
sudo systemctl start css.service
Console Commands
These commands are used in the server console or via RCON.
| Command | Description |
|---|---|
status | Shows connected players and their ID |
changelevel <map> | Change the map |
kick <player> | Kick a player |
kickid <userid> | Kick a player by their ID |
banid <minutes> <steamid> kick | Ban a player (0 = permanent) |
writeid | Save the ban list to banned_user.cfg |
say <message> | Send a message to all players |
exec server.cfg | Reload the configuration |
quit | Stop the server |
Using RCON from the Game
Your IP address must be allowed on TCP port 27015 in the firewall.
In the game console (² or ~ key):
rcon_address YOUR_SERVER_IP:27015
rcon_password YourPassword
rcon status
Automatic Backup
Backup Script
sudo nano /home/css/backup.sh
#!/bin/bash
BACKUP_DIR="/home/css/backups"
SERVER_DIR="/home/css/css-server"
DATE=$(date +%Y-%m-%d_%H-%M-%S)
mkdir -p $BACKUP_DIR
# Backup the configuration
tar -czf $BACKUP_DIR/css_$DATE.tar.gz -C $SERVER_DIR cstrike/cfg
# Delete backups older than 7 days
find $BACKUP_DIR -name "css_*.tar.gz" -mtime +7 -delete
echo "Backup completed: css_$DATE.tar.gz"
sudo chown css:css /home/css/backup.sh
sudo chmod +x /home/css/backup.sh
If you install extensions, add cstrike/addons to the tar command.
Schedule Backup
sudo crontab -u css -e
Add:
# Backup every day at 4 AM
0 4 * * * /home/css/backup.sh
Connecting to the Server
Players can connect via:
- Launch Counter-Strike Source
- Open the game console
- Type:
connect YOUR_SERVER_IP:27015 - If a password is configured:
password YourPasswordbefore connecting
You can also add the server to your Steam favorites (View menu, Servers, Favorites tab).
Troubleshooting
The server won't start
- Check the logs:
sudo journalctl -u css.service -n 100 - Check that the installation is complete (run the
app_updatecommand again) - Look for a missing library:
ldd ~/css-server/srcds_linux | grep "not found", then install the corresponding 32-bit package
libtinfo.so.5 or libncurses.so.5 Warning
If the message WARNING: Failed to load 32-bit libtinfo.so.5 or libncurses.so.5 appears at startup despite the dependencies being installed, create symbolic links to the version 6 files:
sudo ln -sf /usr/lib/i386-linux-gnu/libtinfo.so.6 /usr/lib/i386-linux-gnu/libtinfo.so.5
sudo ln -sf /usr/lib/i386-linux-gnu/libncurses.so.6 /usr/lib/i386-linux-gnu/libncurses.so.5
If the .so.6 files do not exist, first install the libncurses6:i386 package.
steamclient.so and steamerrorreporter Errors
Log in as the css user, then create the links to the SteamCMD files:
sudo -u css bash
mkdir -p ~/.steam/sdk32
ln -sf ~/steamcmd/linux32/steamclient.so ~/.steam/sdk32/steamclient.so
ln -sf ~/steamcmd/linux32/steamerrorreporter ~/css-server/bin/steamerrorreporter
exit
Players can't connect
-
Check that port 27015 is open over UDP:
sudo ufw statussudo iptables -L INPUT -n --line-numbers | grep 27015sudo nft list ruleset | grep 27015 -
Check that the server is listening:
ss -ulnp | grep 27015 -
Test from another machine with
nc -zvu YOUR_SERVER_IP 27015
The server doesn't appear in the list
- Check that
sv_lan 0is set in server.cfg - Wait a few minutes after startup
- Check that the server has Internet access
- Add a GSLT token with
+sv_setsteamaccountto be listed among the public servers
Performance Issues
- Reduce
+maxplayersif the server is overloaded - Disable unnecessary extensions in
cstrike/addons - Schedule regular restarts
FAQ
Which ports need to be opened?
In addition to the server port (27015 over UDP), these ports are required by Steam. They allow the server to receive replies from the Steam servers when your firewall blocks incoming traffic by default:
UFW:
sudo ufw allow proto udp from any port 27000:27030 to any port 1025:65535
sudo ufw allow proto udp from any port 4380 to any port 1025:65535
sudo ufw reload
iptables:
sudo iptables -A INPUT -p udp -m udp --sport 27000:27030 --dport 1025:65535 -j ACCEPT
sudo iptables -A INPUT -p udp -m udp --sport 4380 --dport 1025:65535 -j ACCEPT
sudo iptables-save | sudo tee /etc/iptables/rules.v4
nftables:
sudo nft add rule inet filter input udp sport 27000-27030 udp dport 1025-65535 accept
sudo nft add rule inet filter input udp sport 4380 udp dport 1025-65535 accept
(echo "flush ruleset"; sudo nft list ruleset) | sudo tee /etc/nftables.conf
I get "Permission denied" when running ./steamcmd.sh
Apply a chmod:
chmod +x /home/css/steamcmd/linux32/steamcmd && chmod +x /home/css/steamcmd/steamcmd.sh
My server stays frozen on "Network: IP, mode MP, dedicated Yes, ports 27015 SV / 27005 CL"
Check that the port is not already in use by another process:
sudo lsof -i :27015
If the port is free, check that the Steam rules from the first question are properly applied.
I get the message "WARNING: setlocale('en_US.UTF-8') failed, using locale: 'C'"
This is not a real problem: only some international characters may display incorrectly. To fix it:
sudo locale-gen en_US.UTF-8
sudo update-locale LANG=en_US.UTF-8
If the locale-gen command is not found, first install the locales package with sudo apt install -y locales.
I get a ulimit error (no permission / can not open file)
Set the open files limit to 2048, the value recommended by Valve. For the current session, before starting the server:
ulimit -n 2048
With systemd, add this line in the [Service] section of the service file, then reload and restart:
LimitNOFILE=2048
sudo systemctl daemon-reload
sudo systemctl restart css.service