This generic guide prepares a Linux machine (Ubuntu or Debian) or Windows Server to host any game server: choosing a host, non-root user, SSH keys, firewall, fail2ban, SteamCMD, Docker, systemd service, monitoring and backups. Allow 1 to 2 hours; then follow the installation guide for your specific game.
Step-by-step installation
Pick a host and a plan (see “Choosing a host”), then order a VPS or dedicated server running Ubuntu LTS or Debian stable.
Log in over SSH with the provided root account and update the system.
Create a non-root user with sudo; never run a game server as root.
Install your public SSH key, then disable root and password logins.
Enable the ufw firewall: deny all inbound, allow SSH then the game's ports.
Install fail2ban to block repeated SSH login attempts.
Install SteamCMD (Steam games) or Docker (community images) depending on your game.
Install the game server using your game's guide, then open its ports (“Ports checker” tool).
Create a systemd service (or a tmux session) to start and restart the server automatically.
Set up monitoring (logs, resources) and tested scheduled backups.
Choosing a host and a plan
- VPS (from a few euros a month): enough for a small server; check the CPU isn't heavily shared, since most games depend on one fast core.
- Dedicated: for several servers or many slots; choose SSD/NVMe and a good CPU clock speed.
- Criteria: location close to players (latency), included DDoS protection, unlimited traffic or a sufficient quota, network firewall (“security group”), snapshots, support. Estimate resources with the “Server resources calculator”.
First login and non-root user
Replace 203.0.113.10 with your server's IP and gameadmin with the name you prefer:
ssh [email protected]
apt update && apt upgrade -y
adduser gameadmin
usermod -aG sudo gameadminSSH keys and sshd hardening
On your computer: ssh-keygen -t ed25519 then ssh-copy-id [email protected]. Test key login in a second terminal BEFORE disabling passwords, then create /etc/ssh/sshd_config.d/99-hardening.conf (Ubuntu 22.04+, Debian 12):
# /etc/ssh/sshd_config.d/99-hardening.conf
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
# Apply: sudo sshd -t && sudo systemctl reload sshufw firewall
Allow SSH before enabling ufw so you don't lock yourself out. Then add your game's ports (FiveM example: 30120 TCP and UDP; each game's ports are in the Ports checker; the “Firewall rules” tool generates the commands). Mirror them in the host's network firewall (OVH, Hetzner, Scaleway…: “security group”).
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow OpenSSH
sudo ufw allow 30120/tcp
sudo ufw allow 30120/udp
sudo ufw enable
sudo ufw status verbosefail2ban
fail2ban temporarily bans addresses that repeatedly fail to log in. Create /etc/fail2ban/jail.local (don't edit jail.conf):
# sudo apt install fail2ban
# /etc/fail2ban/jail.local
[sshd]
enabled = true
maxretry = 5
findtime = 10m
bantime = 1h
# sudo systemctl enable --now fail2ban
# sudo fail2ban-client status sshdSteamCMD (Steam games)
Manual installation from Valve's official archive (as gameadmin, not root). Replace APPID with your game's dedicated server ID (see SteamDB or the game's guide). Some servers require a Steam account instead of “anonymous”: check the game's documentation.
sudo apt install -y lib32gcc-s1 curl ca-certificates
mkdir -p ~/steamcmd && cd ~/steamcmd
curl -sqL "https://steamcdn-a.akamaihd.net/client/installer/steamcmd_linux.tar.gz" | tar zxvf -
./steamcmd.sh +force_install_dir ~/server +login anonymous +app_update APPID validate +quitDocker (community images)
Docker's convenience script suits testing; for production, follow the apt repository installation on docs.docker.com. You must log out and back in after joining the docker group. Containers published with -p bypass ufw: also restrict them with the host's firewall.
curl -fsSL https://get.docker.com -o get-docker.sh
sudo sh get-docker.sh
sudo usermod -aG docker gameadmin
# log out, log back in, then:
docker run --rm hello-worldsystemd service
Create /etc/systemd/system/gameserver.service (adapt User, WorkingDirectory and ExecStart to your game's launch script), then: sudo systemctl daemon-reload && sudo systemctl enable --now gameserver. Logs: journalctl -u gameserver -f.
[Unit]
Description=Game server
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
User=gameadmin
WorkingDirectory=/home/gameadmin/server
ExecStart=/home/gameadmin/server/start.sh
Restart=on-failure
RestartSec=10
LimitNOFILE=65536
[Install]
WantedBy=multi-user.targetAlternative: tmux
tmux keeps the server running after SSH disconnects and gives access to its console (handy for commands). Detach with Ctrl+B then D. It doesn't restart the server after a crash or reboot: prefer systemd for production.
sudo apt install -y tmux
tmux new -s game
# inside tmux: run ./start.sh, then press Ctrl+B then D
tmux attach -t gameWindows Server variant
Connect with Remote Desktop (restrict port 3389 to your IP or use a VPN), install SteamCMD or the game server in C:\gameserver, open ports in PowerShell (administrator) and start the server at boot with a scheduled task. Schedule Windows Update reboots to avoid unplanned downtime.
New-NetFirewallRule -DisplayName "Game UDP 27015" -Direction Inbound -Protocol UDP -LocalPort 27015 -Action Allow
New-NetFirewallRule -DisplayName "Game TCP 27015" -Direction Inbound -Protocol TCP -LocalPort 27015 -Action Allow
schtasks /Create /TN "GameServer" /TR "C:\gameserver\start.bat" /SC ONSTART /RU SYSTEM /RL HIGHEST /FHome hosting: port forwarding
- Give the machine a fixed local IP (DHCP reservation in the router).
- In the router, forward (NAT) each game port, with the right protocol, to that local IP.
- Also open the machine's firewall. Test from outside (4G/5G), not from the local network.
- If your ISP uses CGNAT (no dedicated public IP), port forwarding is impossible: ask for a public IP, or use a VPS or a tunnel.
- Exposing your personal IP carries risks (targeted DDoS): a protected VPS is safer for a public server.
DDoS notes
- The machine's firewall isn't enough against a volumetric attack: protection must happen upstream, at the host.
- Check what the plan's anti-DDoS covers (UDP/game protocols, “gaming” mode): it isn't the same for every host.
- Don't disclose the origin IP if you use a proxy or tunnel; don't expose RCON or web consoles.
Monitoring
Useful commands: service logs, ports actually listening (compare with the firewall), CPU/RAM load and disk space. For continuous monitoring add a tool such as Netdata or Prometheus, with alerts on RAM and disk.
journalctl -u gameserver -f
sudo ss -lntup
htop
free -h
df -hBackups
Back up the world and configuration daily, keep several versions and copy them off the server. The “Backup script generator” tool produces a full script with retention; minimal example (crontab):
30 4 * * * tar -czf /backups/gameserver-$(date +\%Y\%m\%d).tar.gz -C /home/gameadmin server && find /backups -name 'gameserver-*.tar.gz' -mtime +7 -deleteTroubleshooting
- Players can't connect: check the protocol (UDP vs TCP), ufw, the host's firewall and that the server is actually listening (sudo ss -lntup).
- “Permission denied (publickey)”: the key isn't in the user's ~/.ssh/authorized_keys, or permissions are too open (chmod 700 ~/.ssh, chmod 600 ~/.ssh/authorized_keys).
- The server gets killed (“Killed”, OOM): not enough memory; check “dmesg | grep -i oom”, add RAM or reduce slots and mods. A swap file limits crashes but slows things down.
- The service restarts in a loop: read “journalctl -u gameserver -n 100”; check paths, permissions (the server must belong to gameadmin) and missing 32-bit libraries for SteamCMD.
- The server doesn't show in the list: the query port is blocked or the server isn't registered; add it on game-rank.com/jeux to get listed.
Frequently asked questions
- VPS or dedicated server for a game server?
- A VPS is enough for a small server or testing. Move to a dedicated server for several servers, many slots or steady performance (no noisy neighbours).
- Ubuntu or Debian?
- Both work and commands are nearly identical. Choose a supported release (Ubuntu LTS or Debian stable) and check the compatibility stated by your game's publisher.
- Do I really need to disable root and password logins?
- It is strongly recommended: exposed servers get thousands of attempts a day. An SSH key and a non-root user remove most of the risk; keep a rescue console at your host.
- Docker or direct installation?
- Direct installation with SteamCMD and systemd is simplest and best documented by publishers. Docker isolates and eases running several servers on one machine, but adds a layer to understand (network, volumes, firewall).
