Skip to main content

How to Create Your Counter-Strike Source Server

This guide explains how to install and configure a dedicated Counter-Strike Source (CSS) server on your Linux VPS or dedicated server.

Order a Server​

To host your Counter-Strike Source server, HostMyServers offers several gaming-optimized options:

Prerequisites​

Resources

The resources listed below correspond to the server's needs and do not take into account the resources already used by the operating system, the installed software or the other services present on the machine. Allow about 10 Mbps for 30 players at tickrate 66 with sv_maxrate 30000, and double that at tickrate 100.

  • SSH access as root or user with sudo
  • 64-bit Linux system (Debian 12/13 or Ubuntu 22.04/24.04 recommended)
  • Active firewall: nftables (recommended), iptables or ufw (use only one firewall tool at a time)
  • Minimum 1 GB of RAM (2 GB recommended)
  • About 5 GB of free disk space
  • Port 27015 UDP accessible (and port 27015 TCP for RCON, from your fixed IP address only)

Required Configuration​

ComponentMinimumRecommended
RAM1 GB2 GB
CPU1 core2 cores
Storage5 GB10 GB SSD
Network100 Mbps1 Gbps
Network Protocol

Counter-Strike Source uses port 27015 over UDP for the game and over TCP for RCON access (remote administration), which must be reachable only from your IP addresses (requires a fixed IP address).

System Update​

sudo apt update && sudo apt upgrade -y

Installing Dependencies​

SteamCMD and the CSS server are 32-bit programs: 32-bit libraries are required. First check that the i386 architecture is enabled:

sudo dpkg --print-foreign-architectures

If the output is empty, run:

sudo dpkg --add-architecture i386
sudo apt update

Then install the required packages:

sudo apt install -y wget tar screen lib32gcc-s1 lib32stdc++6

Creating a Dedicated User​

For security reasons, create a dedicated user:

sudo adduser --disabled-password --gecos "" css

Firewall Configuration​

Open port 27015 over UDP for players. Port 27015 over TCP is RCON: restrict it to your fixed IP address (replace YOUR_IP).

With UFW​

sudo ufw allow 27015/udp
sudo ufw allow from YOUR_IP to any port 27015 proto tcp
sudo ufw reload

With iptables​

sudo iptables -A INPUT -p udp --dport 27015 -j ACCEPT
sudo iptables -A INPUT -p tcp -s YOUR_IP --dport 27015 -j ACCEPT
sudo iptables-save | sudo tee /etc/iptables/rules.v4

Saving the rules across reboots requires the iptables-persistent package.

With nftables​

These commands use the inet filter table and the input chain, present by default in /etc/nftables.conf on Debian.

sudo nft add rule inet filter input udp dport 27015 accept
sudo nft add rule inet filter input ip saddr YOUR_IP tcp dport 27015 accept
(echo "flush ruleset"; sudo nft list ruleset) | sudo tee /etc/nftables.conf
RCON Security

Never open TCP port 27015 to everyone: it gives access to RCON. Without a fixed IP address, do not open this port and use an SSH tunnel instead.

Installing SteamCMD​

Log in as the css user:

sudo -u css bash
cd ~

Create the directories and download SteamCMD:

mkdir -p ~/steamcmd ~/css-server
cd ~/steamcmd
wget https://steamcdn-a.akamaihd.net/client/installer/steamcmd_linux.tar.gz
tar -xzf steamcmd_linux.tar.gz

Downloading the CSS Server​

Start the server installation (application ID 232330):

./steamcmd.sh +force_install_dir /home/css/css-server +login anonymous +app_update 232330 validate +quit
Tip

If the installation stops with an error, simply run the same command again: SteamCMD resumes where it left off.

When it finishes, the message Success! App '232330' fully installed. is displayed.

Server Configuration​

server.cfg File​

Create the configuration file:

nano ~/css-server/cstrike/cfg/server.cfg

Basic Configuration​

hostname "My CSS Server"
sv_password ""
rcon_password "ChangeMe"
sv_region 3
sv_lan 0
sv_cheats 0
mp_timelimit 30
mp_freezetime 6
mp_friendlyfire 0
mp_autoteambalance 1
mp_limitteams 2
sv_alltalk 0

Custom Advanced Configuration​

Example of a more complete configuration, to adapt to your community:

// Server.cfg created by Let's Go
// For the Free 4 Funs community
// Shared for hostmyservers.fr
// Version 1.2
// -------------------------------------------------------------------------------------
// SERVER SETTINGS
// -------------------------------------------------------------------------------------

// -------------------------------------------------------------------------------------
// RCON security and password
// -------------------------------------------------------------------------------------
// RCON password (to be changed)
rcon_password "changeme"

// Password to join the server (public server: leave empty)
sv_password ""

// -------------------------------------------------------------------------------------
// Server identification
// -------------------------------------------------------------------------------------
// Server name
hostname "My CSS Server"
sv_region 3
sv_lan 0
// Ban duration (in minutes) after failed RCON access attempts
sv_rcon_banpenalty 60
// Maximum number of failed RCON access attempts before banning
sv_rcon_maxfailures 10
// Minimum number of failed RCON access attempts before banning
sv_rcon_minfailures 5
// Time window (in seconds) over which failures are counted (see sv_rcon_minfailures)
sv_rcon_minfailuretime 900

// -------------------------------------------------------------------------------------
// Server configuration
// -------------------------------------------------------------------------------------

mp_allowspectators 1
mp_autocrosshair 0
mp_autokick 0
mp_autoteambalance 0
mp_buytime 0.5
mp_c4timer 30
mp_chattime 8
mp_fadetoblack 0
mp_flashlight 1
mp_footsteps 1
mp_forcecamera 0
mp_forcerespawn 0
mp_fraglimit 0
mp_freezetime 4
mp_friendlyfire 1
mp_hostagepenalty 0
mp_limitteams 1
mp_maxrounds 0
mp_playerid 0
mp_roundtime 3
mp_spawnprotectiontime 5
mp_startmoney 16000
mp_timelimit 20
mp_tkpunish 0
mp_weaponstay 1
mp_winlimit 0
sv_accelerate 5
sv_gravity 800
sv_maxspeed 320
sv_pausable 0
sv_timeout 40

// -------------------------------------------------------------------------------------
// Security
// -------------------------------------------------------------------------------------
sv_cheats 0
sv_consistency "1"
sv_pure "2"
sv_pure_kick_clients "1"

// -------------------------------------------------------------------------------------
// Server logs
// -------------------------------------------------------------------------------------
log on
sv_logbans 1
sv_logecho 1
sv_logfile 1
sv_log_onefile 1
sv_logsdir logs
mp_logdetail 3

// -------------------------------------------------------------------------------------
// Server bandwidth
// -------------------------------------------------------------------------------------

// Fast download (FastDL): address of a web server hosting the files
//sv_downloadurl "https://xxxxxxxxxxxxxxxxxxx"
// Allow downloads
sv_allowdownload 1
// Allow file uploads by players (sprays, etc.)
sv_allowupload 1

// Configuration optimized for a tickrate of 100
// Requires the Tickrate Enabler extension for CS:Source and the -tickrate 100 launch parameter
// Unlimited server-side FPS (0 = unlimited, uses more resources)
fps_max 0

// -------------------------------------------------------------------------------------
// Do not change these values if you do not know what you are doing
// sv_maxrate 0: unlimited rate
// sv_maxrate 30000: 30,000 bytes/s (about 0.24 Mbps) per player
// -------------------------------------------------------------------------------------
net_queued_packet_thread 0
sv_mincmdrate 75
sv_maxcmdrate 101
sv_maxrate 0
sv_minrate 20000
sv_maxupdaterate 101
sv_minupdaterate 75

// -------------------------------------------------------------------------------------
// Ban management
// -------------------------------------------------------------------------------------
// Loads the list of players banned by SteamID and by IP address
// (files to be placed in cstrike/cfg)
exec banned_user.cfg
exec banned_ip.cfg

// -------------------------------------------------------------------------------------
// Bot management
// -------------------------------------------------------------------------------------
// To enable bots, remove the // in front of the next line
// (the bot.cfg file must be located in cstrike/cfg)
//exec bot.cfg

// -------------------------------------------------------------------------------------
// Server statistics
// -------------------------------------------------------------------------------------
sv_stats 1
sv_filterban 1

echo ==============================
echo Server.cfg correctement charge
echo ==============================
echo ===============================
echo Visitez wiki.free4funs.ovh
echo Visitez hostmyservers.fr
echo ===============================
echo ===============================
echo Server.cfg Config By Lets'Go
echo ===============================
Security

Choose a long and unique rcon_password. Anyone who knows it can administer your server.

Main Parameters​

ParameterDescription
hostnamePublic name of the server
sv_passwordPassword to join (empty = public)
rcon_passwordRemote administration password
sv_regionRegion: 3 = Europe, 0 = US East, 4 = Asia, 255 = worldwide
sv_lan0 = server visible on the Internet, 1 = local network only
mp_timelimitDuration of a map in minutes
mp_freezetimeFreeze time at the start of a round, during which players buy their equipment (seconds)
mp_friendlyfireFriendly fire (0 = disabled, 1 = enabled)
sv_alltalkVoice chat between the two teams (0 or 1)

GSLT Token (Optional)​

GSLT Token

The GSLT (Game Server Login Token) is not mandatory but recommended: it allows your server to be listed among the public Steam servers.

To generate it, log in to your Steam account and go to the Steam Game Server Account Management.

Creating the token has a few prerequisites:

  • Your Steam account must not be community banned or locked
  • Your Steam account must not be limited
  • Your Steam account must have a phone number registered
  • Your Steam account must own the game for which you are creating a game server account
  • Your Steam account can create up to 1000 game server accounts

In the App ID of the base game field, enter 240. You can add a memo to remind yourself which server it is for, then finish by clicking the Create button.

To use the token, add it to the launch line:

+sv_setsteamaccount YOUR_TOKEN
Tip

Add the parameter to all your launch lines: the first launch, the ExecStart line of the systemd service and the command launched with screen.

First Launch​

cd ~/css-server
./srcds_run -game cstrike -console +map de_dust2 +maxplayers 24 -port 27015

Once startup is complete, the console displays the status of the connection to the Steam servers. To stop the server, type quit.

Launch Optimization​

Launch Parameters​

ParameterDescription
-game cstrikeGame to launch (mandatory)
+mapStarting map
+maxplayersMaximum number of players (up to 64)
-portServer port (27015 by default)
-ipIP address to listen on
-tickrate 100Simulation frequency (66 by default). Increases CPU load and requires the Tickrate Enabler extension
-norestartPrevents the script from restarting the server if it stops (useful with systemd)
-consoleRuns in console mode
-debuglog file_nameWrites the debug output to the file
-highMaximum priority for the server process
-nohltvDisables SourceTV
-nobotsDisables bots
-insecureDisables VAC protection (see the warning below)
+sv_setsteamaccountGSLT token (optional, see the dedicated section)
-insecure Parameter

-insecure disables VAC protection: only use this parameter for testing, as it leaves the door open to cheaters.

Changing the Port​

./srcds_run -game cstrike -console +map de_dust2 +maxplayers 24 -port 27016

Don't forget to open the new port in the firewall.

File Structure​

PathDescription
cstrike/cfg/Configuration files
cstrike/cfg/server.cfgMain configuration
cstrike/cfg/banned_user.cfgBanned players (SteamID)
cstrike/cfg/banned_ip.cfgBanned IP addresses
cstrike/maps/Installed maps
cstrike/addons/Extensions (Metamod, SourceMod)
cstrike/logs/Log files

Configuration as systemd Service​

Create Service File​

Exit the css user's session (exit) to return to your administrator account, then create the service file:

sudo nano /etc/systemd/system/css.service

File content:

[Unit]
Description=Counter-Strike Source Server
After=network.target

[Service]
Type=simple
User=css
Group=css
WorkingDirectory=/home/css/css-server
Environment=TERM=xterm
ExecStart=/home/css/css-server/srcds_run -game cstrike -console -norestart +map de_dust2 +maxplayers 24 -port 27015
Restart=on-failure
RestartSec=20

[Install]
WantedBy=multi-user.target

Enable and Start Service​

sudo systemctl daemon-reload
sudo systemctl enable css.service
sudo systemctl start css.service

Management Commands​

# Check status
sudo systemctl status css.service

# Stop server
sudo systemctl stop css.service

# Restart server
sudo systemctl restart css.service

# View logs
sudo journalctl -u css.service -f
Server Console

With systemd, the server console is not interactive. To send commands, use RCON from the game or launch the server with screen (see below).

Launching with screen (Alternative)​

Only One Launch Mode

If the systemd service is started, stop it first (sudo systemctl stop css.service): two servers cannot use the same port.

sudo -u css bash
cd ~/css-server
screen -S css
./srcds_run -game cstrike -console +map de_dust2 +maxplayers 24 -port 27015

To detach: Ctrl+A then D

To reattach: screen -r css

Launching in the Background with a Log​

sudo -u css bash
cd ~/css-server
screen -AdmSL css ./srcds_run -game cstrike -console +map de_dust2 +maxplayers 24 -port 27015
OptionDescription
-AAdapts the window to the terminal size
-d -mStarts the session detached, in the background
-S cssSession name
-LWrites the server output to a log file

The screenlog.0 file is created in the folder where the command is run (~/css-server) and contains all the server-side output. To follow it live:

tail -f ~/css-server/screenlog.0

In case of a startup error, this is the first file to check. To return to the server console: screen -r css

Tip

The screenlog.0 file grows with each launch. Remember to purge or delete it regularly.

Server Update​

Stop Server​

sudo systemctl stop css.service

Download the New Version​

sudo -u css bash
cd ~/steamcmd
./steamcmd.sh +force_install_dir /home/css/css-server +login anonymous +app_update 232330 validate +quit
exit

Restart Server​

sudo systemctl start css.service

Console Commands​

These commands are used in the server console or via RCON.

CommandDescription
statusShows connected players and their ID
changelevel <map>Change the map
kick <player>Kick a player
kickid <userid>Kick a player by their ID
banid <minutes> <steamid> kickBan a player (0 = permanent)
writeidSave the ban list to banned_user.cfg
say <message>Send a message to all players
exec server.cfgReload the configuration
quitStop the server

Using RCON from the Game​

Your IP address must be allowed on TCP port 27015 in the firewall.

In the game console (² or ~ key):

rcon_address YOUR_SERVER_IP:27015
rcon_password YourPassword
rcon status

Automatic Backup​

Backup Script​

sudo nano /home/css/backup.sh
#!/bin/bash
BACKUP_DIR="/home/css/backups"
SERVER_DIR="/home/css/css-server"
DATE=$(date +%Y-%m-%d_%H-%M-%S)

mkdir -p $BACKUP_DIR

# Backup the configuration
tar -czf $BACKUP_DIR/css_$DATE.tar.gz -C $SERVER_DIR cstrike/cfg

# Delete backups older than 7 days
find $BACKUP_DIR -name "css_*.tar.gz" -mtime +7 -delete

echo "Backup completed: css_$DATE.tar.gz"
sudo chown css:css /home/css/backup.sh
sudo chmod +x /home/css/backup.sh
Tip

If you install extensions, add cstrike/addons to the tar command.

Schedule Backup​

sudo crontab -u css -e

Add:

# Backup every day at 4 AM
0 4 * * * /home/css/backup.sh

Connecting to the Server​

Players can connect via:

  1. Launch Counter-Strike Source
  2. Open the game console
  3. Type: connect YOUR_SERVER_IP:27015
  4. If a password is configured: password YourPassword before connecting

You can also add the server to your Steam favorites (View menu, Servers, Favorites tab).

Troubleshooting​

The server won't start​

  • Check the logs: sudo journalctl -u css.service -n 100
  • Check that the installation is complete (run the app_update command again)
  • Look for a missing library: ldd ~/css-server/srcds_linux | grep "not found", then install the corresponding 32-bit package

libtinfo.so.5 or libncurses.so.5 Warning​

If the message WARNING: Failed to load 32-bit libtinfo.so.5 or libncurses.so.5 appears at startup despite the dependencies being installed, create symbolic links to the version 6 files:

sudo ln -sf /usr/lib/i386-linux-gnu/libtinfo.so.6 /usr/lib/i386-linux-gnu/libtinfo.so.5
sudo ln -sf /usr/lib/i386-linux-gnu/libncurses.so.6 /usr/lib/i386-linux-gnu/libncurses.so.5

If the .so.6 files do not exist, first install the libncurses6:i386 package.

steamclient.so and steamerrorreporter Errors​

Log in as the css user, then create the links to the SteamCMD files:

sudo -u css bash
mkdir -p ~/.steam/sdk32
ln -sf ~/steamcmd/linux32/steamclient.so ~/.steam/sdk32/steamclient.so
ln -sf ~/steamcmd/linux32/steamerrorreporter ~/css-server/bin/steamerrorreporter
exit

Players can't connect​

  • Check that port 27015 is open over UDP:

    sudo ufw status
    sudo iptables -L INPUT -n --line-numbers | grep 27015
    sudo nft list ruleset | grep 27015
  • Check that the server is listening: ss -ulnp | grep 27015

  • Test from another machine with nc -zvu YOUR_SERVER_IP 27015

The server doesn't appear in the list​

  • Check that sv_lan 0 is set in server.cfg
  • Wait a few minutes after startup
  • Check that the server has Internet access
  • Add a GSLT token with +sv_setsteamaccount to be listed among the public servers

Performance Issues​

  • Reduce +maxplayers if the server is overloaded
  • Disable unnecessary extensions in cstrike/addons
  • Schedule regular restarts

FAQ​

Which ports need to be opened?​

In addition to the server port (27015 over UDP), these ports are required by Steam. They allow the server to receive replies from the Steam servers when your firewall blocks incoming traffic by default:

UFW:

sudo ufw allow proto udp from any port 27000:27030 to any port 1025:65535
sudo ufw allow proto udp from any port 4380 to any port 1025:65535
sudo ufw reload

iptables:

sudo iptables -A INPUT -p udp -m udp --sport 27000:27030 --dport 1025:65535 -j ACCEPT
sudo iptables -A INPUT -p udp -m udp --sport 4380 --dport 1025:65535 -j ACCEPT
sudo iptables-save | sudo tee /etc/iptables/rules.v4

nftables:

sudo nft add rule inet filter input udp sport 27000-27030 udp dport 1025-65535 accept
sudo nft add rule inet filter input udp sport 4380 udp dport 1025-65535 accept
(echo "flush ruleset"; sudo nft list ruleset) | sudo tee /etc/nftables.conf

I get "Permission denied" when running ./steamcmd.sh​

Apply a chmod:

chmod +x /home/css/steamcmd/linux32/steamcmd && chmod +x /home/css/steamcmd/steamcmd.sh

My server stays frozen on "Network: IP, mode MP, dedicated Yes, ports 27015 SV / 27005 CL"​

Check that the port is not already in use by another process:

sudo lsof -i :27015

If the port is free, check that the Steam rules from the first question are properly applied.

I get the message "WARNING: setlocale('en_US.UTF-8') failed, using locale: 'C'"​

This is not a real problem: only some international characters may display incorrectly. To fix it:

sudo locale-gen en_US.UTF-8
sudo update-locale LANG=en_US.UTF-8

If the locale-gen command is not found, first install the locales package with sudo apt install -y locales.

I get a ulimit error (no permission / can not open file)​

Set the open files limit to 2048, the value recommended by Valve. For the current session, before starting the server:

ulimit -n 2048

With systemd, add this line in the [Service] section of the service file, then reload and restart:

LimitNOFILE=2048
sudo systemctl daemon-reload
sudo systemctl restart css.service