Squad Dedicated Server Setup: Windows, Linux, Ports and Licensing
Your Squad server can start successfully and still leave players unable to find or join it. The real test comes when players connect, the match fills, and your setup has to handle the load.

A Squad dedicated server hosts matches independently of the player’s game client, giving you control over settings, maps, and admin access. Install the free Windows or Linux server tool through SteamCMD using App ID 403240. Unlicensed servers appear under Custom Servers. Listing in the main Server Browser requires an Offworld server license.
This guide takes you through installation, ports, configuration, and connection checks so you can verify that players can reach your server. You’ll also learn how to plan hardware, manage mods, and troubleshoot common problems before increasing your player count.
Squad Dedicated Server Quick Facts
| Item | Current Detail |
|---|---|
| Main Game App ID | 393380 |
| Dedicated Server App ID | 403240 |
| Application Type | Free Steam Tool |
| Supported Server OS | Windows 64-bit and Linux 64-bit |
| Latest Verified Version | Squad 10.6 Hotfix 2 -2 October 2026 |
| Installed Server Build Verification | Verify the installed app manifest’s buildid after updating |
| Current Engine | Unreal Engine 5.7 |
| Main Installation Method | SteamCMD anonymous login |
| Main Configuration Directory | SquadGame/ServerConfig/ |
| Default Game Port | 7787 UDP |
| Default Query Port | 27165 UDP; account for the paired query allocation where required |
| Default RCON Port | 21114 TCP, restricted to trusted management access |
| Workshop Parent App ID | 393380 |
| Unlicensed Server Location | Custom Servers |
Squad Server Updates Relevant to This Guide
Offworld published Squad 10.6 Hotfix 2 on 2 October 2026, addressing server and client desynchronization after revives.
Later fixes matter when diagnosing mod-related joins: Squad 10.5.3 addressed outdated-mod detection and related connection failures.
Squad 10.5 updated the Mod SDK. Existing mods needed to be recooked, and outdated Workshop files could cause clients to remain in an infinite loading loop.
Squad 10.4 moved the game from Unreal Engine 5.5 to Unreal Engine 5.7, as documented in the official Steam announcements.
Squad 10.3 introduced AllowFireteamLayersInRotation, PrepTimeStandard, and PrepTimeSmallScale for controlling Fireteam rotation and staging times.
These settings have different scopes. AllowFireteamLayersInRotation controls Fireteam layer eligibility; the preparation-time settings apply to their documented modes. Check the 10.3 release notes and current configuration comments before changing them.
After updating, locate appmanifest_403240.acf in the relevant Steam library and record its buildid. A Steam Build ID and a named Squad release are different identifiers.
What a Squad Dedicated Server Is
A Squad dedicated server hosts matches independently of players’ game clients. It can stay online without connected players while the host, network, and server process remain operational.
You control server rules, admin permissions, reserved slots, layer rotation, and restarts.
Who This Is For
Use one for public communities, scrims, clan events, or private matches. Licensed servers must remain public; use an unlicensed server for password-protected events.
Prerequisites Before Installing a Squad Server
Do not start with SteamCMD. Start with the basics that decide if your server will be reachable, stable, and easy to maintain.
Use this checklist. Completing these checks reduces avoidable setup problems.
Pre-Install Checklist
- Public IP Or A Routable Host
- For internet players, you need a host with a working inbound connection path. A LAN-only test does not require public internet reachability.
- A “public IP” is the cleanest case.
- CGNAT can prevent unsolicited inbound IPv4 connections without an ISP-supported mapping or public address. Double NAT can work if the required forwarding is configured at both routers.
- If inbound routing is unavailable, ask the ISP about a public address or supported mapping, or use a host with the required inbound access.
- Admin Access To Firewall And Network Rules
- You must be able to open ports on:
- The server OS firewall, and
- The network edge (router, cloud firewall, provider panel)
- A missing inbound rule is one possible cause of a missing listing; verify advertising, browser category, versions, and service availability too.
- You must be able to open ports on:
- Enough Disk Space For Updates And Rollbacks
- You need space for:
- The base server install
- Future updates
- Logs
- Mod content if you use it
- Backup copy of your config files
- Measure the installed files, Workshop content, logs, and retained backups before choosing disk capacity. Leave working space for updates; this guide does not establish a universal minimum disk size.
- You need space for:
- A Restart and Maintenance Plan
- Monitor memory, logs, TPS, and connection behavior over time. Use observed changes to choose an appropriate maintenance interval.
- Pick a restart window that fits your player base.
- Publish routine maintenance windows and notify players before planned interruptions.
- A Place To Store Configs And Backups
- Treat configs as assets.
- Store backup copies of these files outside the main install folder; keep the active files in the configuration directory the server reads:
- Server.cfg
- Admins.cfg
- Rcon.cfg
- rotation files
- any custom messages or rules files
- Test how to restore known-good configuration files. Configuration backups do not restore server binaries or guarantee compatibility with an older mod package.
What To Decide Before You Install
- Your Target Player Count
- For a 100-player target, verify sustained per-core performance, peak memory use, packet loss, jitter, and TPS under the intended workload.
- A smaller population may need fewer resources, but layers, mods, and measured load still determine the appropriate configuration.
- Your Operating System
- Windows often feels simpler for first-time hosts.
- Linux often feels cleaner for long-term operation and automation.
- Pick the OS you can manage at 2 AM when something breaks.
Squad Dedicated Server Download And Install With SteamCMD
SteamCMD is the most reliable way to install and update a server. It is scriptable, repeatable, and easy to automate later.
Before using these scripts, install SteamCMD using Valve’s platform instructions, install the platform-specific dependencies described in Valve’s instructions, and confirm the executable location. Stop an existing game-server process before updating its files.
Your goal is simple:
- Install the dedicated server files into a clean folder
- Update using the same command every time
- Validate when you suspect corruption or odd crashes
Folder Layout That Stays Clean
Use a layout you can back up and troubleshoot fast.
- SteamCMD folder
- Contains SteamCMD only
- Example: C:\steamcmd\ or /opt/steamcmd/
- Squad server folder
- Contains the dedicated server files only
- Example: C:\servers\squad\ or /opt/squad/
- Config backup folder
- Contains copies of your config files
- Example: C:\servers\squad-config-backups\ or /opt/squad-config-backups/
This split prevents one common failure: you reinstall the server and overwrite the only working config you had.
SteamCMD Install Method (Windows And Linux)
Windows: Copy/Paste Install Script
Create a file named update_squad.txt inside your SteamCMD folder.
Use this structure:
- It stops subsequent SteamCMD commands after a reported failure; a failed installation may still need a retry or validation.
- It logs in anonymously.
- It installs into your chosen folder.
- It installs or updates the dedicated server without running a full file validation during every routine update.
Set the install path below, then check the SteamCMD and script paths in the batch wrapper:
@ShutdownOnFailedCommand 1
@NoPromptForPassword 1
force_install_dir C:\servers\squad
login anonymous
app_update 403240
quit
Now create a file named install_or_update.bat:
@echo off
set "STEAMCMD=C:\steamcmd\steamcmd.exe"
set "SCRIPT=C:\steamcmd\update_squad.txt"
"%STEAMCMD%" +runscript "%SCRIPT%"
pause
Run install_or_update.bat.
What this gives you:
- One button to install.
- The same button to update later.
- An interactive updater; remove pause and add logging, failure handling, and shutdown coordination before scheduling it.
Linux: Copy/Paste Install Script
Confirm that /usr/games/steamcmd is the installed executable path and replace it if necessary. The account running this script must have write access to /opt/squad.
Run the Linux installation and game process from an unprivileged account. From that account, use sudo only to create a server directory owned by the current user:
sudo install -d -o `id -un` -g `id -gn` /opt/squad
Create an update script named install_or_update_squad.sh:
#!/bin/bash
set -e
STEAMCMD="/usr/games/steamcmd"
INSTALL_DIR="/opt/squad"
mkdir -p "$INSTALL_DIR"
"$STEAMCMD" +@ShutdownOnFailedCommand 1 \
+force_install_dir "$INSTALL_DIR" \
+login anonymous \
+app_update 403240 \
+quit
Make it executable:
chmod +x install_or_update_squad.sh
Run it:
./install_or_update_squad.sh
Why this matters:
- It turns updates into a single repeatable command.
- It reduces human error.
- It makes it easy to automate daily checks later.
Launch The Squad Dedicated Server
These commands are initial launch tests. For unattended operation, supervise the process with a service manager using an unprivileged account and the server installation as its working directory; test restart and shutdown behavior before scheduling maintenance.
Windows Launch Example:
cd /d "C:\servers\squad"
"C:\servers\squad\SquadGame\Binaries\Win64\SquadGameServer.exe" Port=7787 QueryPort=27165 beaconport=15000 FIXEDMAXPLAYERS=80 RANDOM=NONE -log
Linux Launch Example:
cd /opt/squad
./SquadGameServer.sh Port=7787 QueryPort=27165 beaconport=15000 FIXEDMAXPLAYERS=80 RANDOM=NONE -log
Change FIXEDMAXPLAYERS to your tested player cap. Additional instances need non-overlapping game and query allocations, including paired ports, plus separate beacon and RCON ports.
Update Command Vs Validate Command (Use Them Correctly)
- Update
- Use for normal patching.
- Run it during your maintenance window.
- It pulls new server files.
- Validate
- Use when you see odd behavior:
- Random crashes after an update,
- Missing files,
- Broken startup after a failed patch.
- Validation takes longer. Do not run it every time unless you need it.
- Use when you see odd behavior:
Your Practical Rule:
- Run update normally.
- When logs, missing files, or failed updates indicate possible file corruption, run SteamCMD with validation enabled.
Windows:
C:\steamcmd\steamcmd.exe +force_install_dir C:\servers\squad +login anonymous +app_update 403240 validate +quit
Linux:
"/usr/games/steamcmd" +force_install_dir "/opt/squad" +login anonymous +app_update 403240 validate +quit
Verify The Install Before You Touch Configs
Do this before you edit Server.cfg or start tuning ports. You want to confirm the install is real and the server process can run.
Verification Checklist
- Confirm The Server Binary Exists
- Your server folder should contain the server executable or launch script.
- If the binary is missing, check SteamCMD output, the installation destination, permissions, and any security-software quarantine before identifying the cause.
- Confirm Logs Generate
- Start the server once.
- You should see a log output window or log files appear.
- No logs usually means:
- Wrong launch path,
- Missing permissions,
- Or the server fails instantly.
- Confirm The Process Stays Running For 5 Minutes
- A server that exits in seconds usually signals:
- Missing dependencies
- Corrupted install
- Or wrong startup parameters.
- Let it run for at least five minutes.
- If it stays up, you can move to configuration with confidence.
- A server that exits in seconds usually signals:
What “Good” Looks Like At This Stage
- The server starts without instantly crashing.
- Logs show normal startup output.
- A running process passes the initial startup check; it does not prove joinability or full-load stability.
Once you pass this step, then it makes sense to move to:
- First boot setup,
- Ports,
- Server.cfg tuning.
Squad Dedicated Server Setup: First Boot Checklist
Do these steps in order. Do not tune anything until you complete the basics. A clean first boot saves you hours later.
Step 1: Start The Server Once To Verify Runtime Files
- Start the server one time with a simple launch command.
- Let it reach a steady “running” state for a minute.
- Stop it cleanly after confirming that runtime logs are created and the expected configuration directory is accessible.
What you gain:
- The test launch confirms that the executable starts correctly and that the expected runtime and configuration paths are accessible.
- You avoid changing configuration before confirming that the installation and file paths are correct.
Step 2: Set ServerName And Basic Identity Settings
- Open your main server config file in the ServerConfig directory.
- Set a server name that tells players what they are joining.
- Keep the name readable in the browser.
- If you plan multiple servers, add a clear label like “#1” and a region tag.
Basic identity settings to lock early:
- Public or private access choice.
- A clear rules line you will enforce.
- A short tag set that helps the right players find you.
Step 3: Set The Player Cap
- Pick a player cap that matches your hardware and your goals.
- Start lower if you are new or still testing stability.
- Raise it only after you confirm stable play during busy hours.
Good Operating Rule:
- Do not chase 100 slots for ego.
- Run the highest slot count you can keep stable.
Step 4: Create Permission Groups And Add An Admin Account
- A simple starting pattern uses two permission groups:
- A moderator group for daily enforcement.
- An admin group with explicitly selected management permissions.
- Add your own SteamID64 to the admin group first.
- Keep the first admin list short until you confirm everything works.
Why this matters:
- You need admin access before you test live joins.
- You do not want to scramble for control after players arrive.
Step 5: Set The RCON Password And Lock It Down
- Set a long RCON password that you do not reuse anywhere else.
- Treat RCON like a control panel. Anyone with access can ruin your server.
- Restrict access by firewall if you can.
Practical Rule:
- If you expose RCON to the open internet, expect trouble.
- If you keep RCON restricted, you reduce risk fast.
Step 6: Set The Rotation File Before You Go Public
- Create your rotation file with a short, proven set of layers.
- Avoid experimental layers on day one.
- Keep the first rotation predictable so you can spot problems.
A good starter rotation does this:
- Mixes popular layers.
- Avoids stacking the heaviest layers back-to-back.
- Keeps matches flowing for new players.
Step 7: Restart And Confirm The Server Advertises
- Restart the server after you change core settings.
- Watch the logs for normal startup.
- Confirm that a licensed server appears in the primary Server Browser or that an unlicensed server appears under Custom Servers.
If the server does not advertise:
- Do not edit ten things at once.
- Fix one layer at a time: config, then ports, then routing.
Done Means You Passed Three Checks
- The server appears in the correct category: the primary Server Browser when licensed or Custom Servers when unlicensed.
- You can join from a different network. Test from a mobile hotspot or a friend’s connection.
- RCON responds. You can run a simple command like listing players without errors.
If a check fails, investigate configuration, networking, versions, mods, and current publisher issues before assigning a cause.
Squad Dedicated Server Requirements: What Actually Matters
Squad server planning should prioritize sustained per-core CPU performance, sufficient memory, stable routing, and measurable TPS under load. Do not select hardware by total core count alone.
RedSwitches Planning Estimates: 50 Vs 80 Vs 100 Players
These figures are planning estimates, not official Squad minimums. Offworld’s published policy lists a minimum of 8 GB RAM and 4 GB additional per game instance; consult the current policy for the applicable allocation. Validate the configuration using your exact layers, mods, peak RAM use, network use, and server TPS.
| Target Player Count | CPU Priority | RAM Target | Storage | Network Target | Notes |
|---|---|---|---|---|---|
| 50 Players | High single-core performance on modern desktop-class CPUs | 16 GB | NVMe | 100–250 Mbps committed | Great for training, events, and smaller communities. |
| 80 Players | High single-core performance with strong sustained boost | 32 GB | NVMe | 250 Mbps–1 Gbps committed | An 80-player cap may provide additional performance headroom, but the ideal cap depends on CPU performance, TPS, layers, mods, and community goals. |
| 100 Players | Top-tier single-core performance with strong sustained clocks | 32–64 GB | NVMe | 1 Gbps committed | Leave resource headroom and monitor server TPS as the population increases. Offworld considers more than 35 TPS healthy, below 25 TPS degraded, and below 15 TPS critical. |
Rules that keep you out of trouble:
- Pick the highest single-core performance you can afford.
- NVMe can reduce storage-related update and loading time, but server restarts and offline updates still interrupt availability.
- Buy a committed network port that matches your peak, not your average.
Allow Headroom For Mods
Mods increase load time and can raise server load during heavy moments.
If you run mods:
- Allow additional resource headroom for mods, based on measured performance under your intended workload.
- Test your chosen mods at the intended player cap, then adjust CPU, RAM, and network capacity where measurements show a bottleneck.
- Keep the mod list short until you prove stability.
What You Should Not Do
- Do not chase more cores over better single-core speed. The main game thread can limit performance, but measure CPU threads, memory, I/O, and networking before identifying the bottleneck.
- Do not run a public 100-player server on weak single-core CPUs. You will feel it when the server fills.
- Check the sustained CPU allocation before choosing a burstable plan. Performance may drop when CPU credits are exhausted or usage exceeds the plan’s baseline allowance.
- Do not cheap out on storage. Slow disk slows updates, restarts, and recovery after crashes.
Squad Dedicated Server Ports: Open, Forward, Verify
Ports, NAT, and interface binding are possible causes of missing listings; also check advertising, browser category, versions, filters, and discovery services. Fix the network path before you touch gameplay settings.
Ports Table: Example Allocations And Conditional Requirements
This table includes inherited dual-protocol guidance for beacon and query traffic; verify those requirements against the actual build and host. RCON uses TCP in these examples. Investigate additional UDP traffic specifically rather than allowing it through an unrestricted inbound range.
| Port | Protocol | Purpose | What To Know |
|---|---|---|---|
| 7787 | UDP | Game traffic (primary) | This carries core gameplay traffic. |
| 7788 | UDP | Game traffic (secondary) | Many setups use the next port for related traffic. |
| 15000 | TCP and UDP | Beacon / discovery | Helps the server show up and stay discoverable. |
| 27165 | TCP and UDP | Steam query (common default) | Many guides use this as the primary query port. |
| 27166 | TCP and UDP | Steam query variant / +1 port | Open this too when you troubleshoot visibility. |
| 21114 | TCP | RCON | Allow only trusted management addresses or a VPN. |
| 30000+ | UDP | High ports used after connect | Investigate the host’s actual requirement; do not open an unrestricted inbound range by default. |
Query port note you should follow:
- If you set a query port in your startup parameters, open that exact port.
- If your server shows locally but not publicly, open both 27165 and 27166 as a fast test.
Firewall Rules: Minimal And Clean
Windows Firewall (Inbound)
Run these in an elevated command prompt:
Replace YOUR_ADMIN_IP in the RCON example with the actual trusted administrator or VPN source address before running it. Remove any existing broad RCON allow rules first, including UDP rules; a narrow allow does not cancel another broad allow.
netsh advfirewall firewall add rule name="Squad Game UDP 7787-7788" dir=in action=allow protocol=UDP localport=7787-7788
netsh advfirewall firewall add rule name="Squad Beacon UDP 15000" dir=in action=allow protocol=UDP localport=15000
netsh advfirewall firewall add rule name="Squad Beacon TCP 15000" dir=in action=allow protocol=TCP localport=15000
netsh advfirewall firewall add rule name="Squad Query UDP 27165-27166" dir=in action=allow protocol=UDP localport=27165-27166
netsh advfirewall firewall add rule name="Squad Query TCP 27165-27166" dir=in action=allow protocol=TCP localport=27165-27166
netsh advfirewall firewall add rule name="Squad RCON TCP 21114 Restricted" dir=in action=allow protocol=TCP localport=21114 remoteip=YOUR_ADMIN_IP
Game ports 7787–7788 use UDP. Verify beacon and query protocol requirements for the current deployment; restrict TCP RCON to trusted management access.
Linux UFW (Inbound)
The OpenSSH profile must match the actual SSH port before UFW is enabled. For RCON, replace YOUR_ADMIN_IP with the trusted administrator or VPN source address and remove any existing broad TCP or UDP RCON allow rules first.
sudo ufw allow OpenSSH
sudo ufw allow 7787:7788/udp
sudo ufw allow 15000/udp
sudo ufw allow 15000/tcp
sudo ufw allow 27165:27166/udp
sudo ufw allow 27165:27166/tcp
sudo ufw allow from YOUR_ADMIN_IP to any port 21114 proto tcp
sudo ufw status
If UFW is already active, apply the rules with:
sudo ufw reload
If UFW is inactive, confirm that SSH is allowed and then enable it with:
sudo ufw enable
Apply required public traffic rules at every relevant firewall layer, and keep RCON limited to the trusted management source or VPN path.
Verify Ports And Browser Visibility (Do This In Order)
1) Confirm The Server Binds To The Correct Interface
- If your host has more than one IP, the server can bind to the wrong one.
- When explicit binding is needed, use an IP assigned to the intended local interface; an unassigned public NAT address is not a valid local bind address.
- Treat “it works on the server machine” as a weak test. External joins matter.
2) Confirm The OS Firewall Allows Inbound Traffic
- Confirm the rule exists.
- Confirm the rule targets the correct port range.
- Confirm the rule targets the correct protocol.
3) Confirm Your Router Or Provider Forwards To The Server
- Home Hosting: Forward ports to the server’s LAN IP.
- Dedicated Hosting: Open ports in the provider firewall panel if they use one.
- Make sure your server’s internal IP does not change after reboots.
4) Check For CGNAT Or Double NAT
- Under CGNAT, unsolicited inbound IPv4 traffic normally cannot reach the server unless the ISP provides port mapping or a public address. Treat public IPv6 as an alternative only after verifying support across the game, host, and clients.
- Ask the ISP about a public address or supported mapping, or use a host with suitable inbound connectivity.
5) Test Join From A Mobile Hotspot
- Disconnect your client PC from your home network.
- Join the server from a mobile hotspot or ask a friend to join.
- This test tells you the truth fast.
If an external join fails, compare logs, versions, mods, advertising, browser category, and network rules before identifying the cause.
Core Configuration: Server.cfg, Admins.cfg, Rcon.cfg, And Passwords
You do not need a “perfect” config on day one. You need a config that makes your server easy to find, easy to run, and hard to abuse.
Server.cfg: Settings That Matter
Focus on discoverability, stability, and clear rules.
Minimal Server.cfg Example
ServerName="My Squad Server"ShouldAdvertise=trueIsLANMatch=falseMaxPlayers=80NumReservedSlots=2PublicQueueLimit=20Tags=
Use the default Server.cfg included with the current server build as the reference for additional options. Existing configuration files may not automatically receive settings introduced by later updates.
- Server Name, Max Players, And Advertising
- Set a server name that tells players what they get in one scan.
- Include your region and your style in the name, not a full paragraph.
- Set your player cap to match your real performance, not your dream cap.
- Keep advertising enabled for a public server. If you disable it, the server can run fine and still stay invisible.
- Reserved Slots And Queue Behavior
- Reserve slots for admins and staff who must join fast during incidents.
- Keep the reserved slot count small. Too many reserved slots annoy regular players and hurt retention.
- Set a queue cap that fits your community. A huge queue sounds good until the queue starts failing and players quit.
- Rotation Mode Selection
- Pick one rotation method and stick to it.
- For a fixed layer rotation, set MapRotationMode=LayerList in Server.cfg and edit LayerRotation.cfg. For a fixed map rotation, use MapRotationMode=LevelList and LevelRotation.cfg. Layer voting uses MapRotationMode=LayerList_Vote with LayerVoting.cfg and VoteConfig.cfg. These files belong in SquadGame/ServerConfig/; check the files and configuration comments included with your installed build before editing.
- Use a layer-based rotation if your community cares about specific match types.
- Use a map-based rotation if you want variety and simple management.
- Do not run experimental rotation logic on launch day. Start predictable, then expand.
- Tags That Help Players Find You
- Use tags that match real player intent.
- Choose tags you will enforce. Do not label a server “new player friendly” if your admins do not support it.
- Keep tags consistent across your Discord rules and your server messages.
Practical Rule: if a setting affects visibility, queue flow, or admin access, lock it early. If a setting only affects preferences, change it later.
Admins.cfg: Permissions That Match Your Team
Your admin file decides if your server stays playable when things go bad. Keep the permission model simple.
Minimal Admins.cfg Example
Group=Admin:changemap,balance,chat,kick,ban,cameraman,pauseGroup=Moderator:changemap,chat,kick,ban
Admin=76561198000000000:Admin //Replace with the administrator's SteamID64Admin=76561198000000001:Moderator //Replace with the moderator's SteamID64
Define groups before assigning users. Check the current default Admins.cfg before adding other permission names.
- Create Two Groups First
- Create a Moderator group for day-to-day enforcement.
- Create an Admin group with the specific management powers your team needs.
- Avoid creating five roles on day one. Extra roles create gaps and confusion.
- Moderator Group Should Cover
- Warnings and kicks for basic rule breaks.
- Temporary bans for repeat behavior.
- Limited match tools if your team trusts moderators.
- Zero access to sensitive config actions unless you train them.
- Admin Group Should Cover
- Full ban control.
- Map and rotation control.
- Password changes for appropriately unlicensed private events; licensed servers must remain public.
- Emergency actions when the server needs fast intervention.
- SteamID64 Mapping Must Stay Clean
- Use SteamID64, not display names.
- Verify each ID before you add it.
- Keep a separate staff list in your docs so you can remove access fast.
Example Structure (Keep It Simple)
- Define groups first.
- Assign people second.
- Use names or handles in comments or a staff register; retain the required numeric identifier in each access entry.
Rcon.cfg And Squad Dedicated Server Password Controls
RCON gives you power. It also gives attackers a target. Treat it like an admin panel, not a convenience feature.
Minimal Rcon.cfg Example
IP=0.0.0.0Port=21114Password=REPLACE_WITH_A_LONG_UNIQUE_PASSWORDMaxConnections=5SecondsBeforeTimeoutCheck=120
Leaving Password empty disables RCON. IP=0.0.0.0 listens on all local interfaces; retain it only with appropriate access restrictions, or bind to the intended local or private interface.
- Strong Password Rules
- Use a long password. Aim for 20+ characters.
- Use a password manager and generate it.
- Never reuse your Discord, email, or panel passwords.
- Rotate the password after staff changes.
- Lock RCON Down With Firewall Rules
- Allow RCON only from trusted admin IPs when you can.
- Block it for the whole internet by default.
- If you cannot restrict by IP, put RCON behind a VPN.
- Keep RCON Private If You Can
- Prefer a private admin network.
- Use a VPN or a secured jump box.
- Use SSH tunneling on Linux if your team knows how.
A restricted RCON path reduces exposure, but credentials, updates, and staff-access controls still require maintenance.
Secure-By-Default Checklist
Use this every time you bring a new server online.
- Set A Strong RCON Password
- Generate it.
- Store it in a shared vault with access control.
- Restrict Admin Access
- Allow RCON from trusted IPs, or run it through a VPN.
- Remove access the same day someone leaves staff.
- Limit Exposure And Connections
- Keep RCON off public networks when possible.
- Avoid sharing credentials in chat.
- Keep staff tools behind accounts, not shared logins.
Admin Workflow And Squad Dedicated Server Tool Stack
Tools do not run a server. Process runs a server. Build a simple workflow your team can follow when the server is full and chaotic.
What You Actually Need
- One RCON Tool Your Team Can Use
- Pick one tool and standardize it.
- Train staff on the same interface so actions stay consistent.
- Use a tool that logs actions if your team is large.
- One Player Moderation Process
- Write rules in plain language.
- Define what counts as a warning, a kick, and a ban.
- Require admins to log the reason for serious actions.
- Keep proof standards simple: screenshots, clips, chat logs, timestamps.
- One Restart And Update Policy
- Set a daily restart window and publish it in server messages.
- Update during low-pop hours.
- Do not patch mid-queue unless a critical fix forces it.
- Keep separate recovery procedures for configuration, mods, and application files; restoring configuration alone cannot undo a game update.
- One Ban Appeal Path
- Give players one place to appeal. Discord works fine.
- Set response expectations so appeals do not rot for weeks.
- Ask for basics: SteamID, reason, date, and their side of the story.
- Keep the tone firm. You run the server. You also stay fair.
Standard Admin Actions That Keep Servers Healthy
Use a consistent ladder. Random enforcement kills trust.
- Warn → Kick → Temp Ban → Perm Ban Ladder
- Warn for first-time minor issues when intent looks sloppy, not malicious.
- Kick when the player ignores the warning or repeats the behavior.
- Temp ban when the player returns and repeats the same pattern.
- Perm ban for clear cheating, harassment, ban evasion, or repeated serious violations.
- Broadcast Rules Without Spamming
- Broadcast only when it helps match flow.
- Remind players of one rule at a time.
- Use short messages that match enforcement.
- Map Change Process That Avoids Chaos
- Announce the change before you force it.
- Use map changes as a last resort during active disputes.
- Keep a short list of “safe layers” that run well on your hardware.
Practical rule: consistency matters more than severity. Players accept strict rules when your staff applies them evenly.
Mods And Map Rotation: A Stable Workflow
Mods and custom layers can grow a community fast. They can also wreck stability if you treat them like plug-and-play.
Mods With Controlled Downtime
- Use A Staging Server For Mod Testing
- Use a separate appropriately unlicensed staging instance, or test while production is offline. Do not password-lock or hide a licensed server.
- Install mods there first.
- Stop the server before installing or updating Workshop content.
Windows:
C:\steamcmd\steamcmd.exe +login anonymous +workshop_download_item 393380 MOD_ID +quit
Linux:
"/usr/games/steamcmd" \
+login anonymous \
+workshop_download_item 393380 MOD_ID \
+quit
- Replace MOD_ID with the Workshop item ID. Squad Workshop content uses the main game App ID 393380, not dedicated-server App ID 403240. After downloading, copy the required mod files into:
SquadGame/Plugins/Mods/
- Verify the server boots, loads layers, and stays stable.
- Update Mods After Squad Updates
- Game updates can break mods.
- Test the updated server with compatible mod versions before updating production.
- Update mods once mod authors push compatible versions.
- Avoid “update everything now” during peak playtime.
- Keep The Mod List Short
- Mods can add compatibility risk, loading work, and resource use, depending on their contents.
- Start with the minimum set that adds real value.
- Remove mods that cause crashes, long loads, or staff headaches.
- Keep A Rollback Plan
- Save a known-good mod list.
- Keep backups of rotation files.
- If a mod is implicated, disable it and remove its dependent rotation or configuration references. Restore only a compatible server-and-mod combination.
Practical Rule: if a mod causes random instability, cut it. Your community wants playable matches more than novelty.
2026 Mod Compatibility Warning
Squad 10.5 updated the Mod SDK and required existing mods to be recooked. Outdated Workshop files may cause an infinite loading loop.
Squad 10.5.3, released on 17 September 2026, fixed mod-related client crashes and a detection issue that allowed clients with mismatched mod files to join servers. Check current release notes and mod compatibility when diagnosing connection failures.
Verify that every mod supports the current Squad build before reopening a production server.
Rotation That Does Not Kill Performance
Rotation is not just variety. Rotation is load management.
- Avoid Heavy Layers On Weak Hardware
- Some layers punish CPU and memory harder.
- If your tick drops or queues disconnect during peak, heavy layers often sit near the cause.
- Build a rotation that fits your real hardware tier.
- Use Exclusions With Intent
- Exclude layers that consistently cause crashes or performance drops.
- Exclude layers your community hates. People leave when the server feels like a coin flip.
- Review exclusions every month so the rotation stays fresh.
- Keep A Low-Pop Rotation File
- For supported layer voting, configure LayerVotingLowPlayers.cfg and LowPlayerCountThreshold in VoteConfig.cfg; a file with an arbitrary name will not activate automatically.
- Use smaller maps or lighter layers when population drops.
- Verify that the voting configuration returns to normal LayerVoting.cfg options when population rises above the configured threshold.
Practical Rule: treat rotation like a product. You are designing match quality, not just picking names from a list.
Licensing Explained: Licensed Vs Unlicensed Servers
Licensing decides where your server appears and what standards you must meet to stay there. Decide whether licensed placement is required before choosing infrastructure, then meet the applicable operating requirements.
Licensed Vs Unlicensed: Where Each Shows Up
- Licensed Server
- Shows in the main, default server browsing experience most players use.
- Provides primary-browser visibility; actual discovery and traffic depend on player behavior and server appeal.
- Faces higher scrutiny. You must keep match quality and admin conduct consistent.
- Unlicensed Server
- Shows under Custom Servers.
- Works fine for testing, training, and early community building.
- Gives you space to learn ops without pressure.
What Licensing Expects From You
Licensing is not “a key.” It is a promise that your server stays playable and your staff stays accountable.
- Admin Coverage
- Offworld’s current licensing policy requires at least 10 active administrators for each licensed server.
- You need staff who can respond fast when matches break down.
- Stable Performance
- Monitor server TPS under full population. More than 35 TPS is healthy, below 25 TPS is degraded, and below 15 TPS is critical under the current licensing policy.
- You must manage restarts, updates, and peak-hour load without drama.
- Hardware That Holds Up
- Dedicated resources matter for high player counts.
- Weak single-core performance will surface as queue pain, stutter, and poor match flow.
- Rules That Match Enforcement
- Your rules must be clear, visible, and enforced the same way every day.
- Random enforcement kills trust.
- A Real Appeal Path
- Players need one clear channel for appeals.
- Your staff needs a simple process to review and respond.
Current Official Licensing Requirements
| Requirement | Current Rule |
|---|---|
| Server Visibility | Publicly accessible; licensed servers cannot be password-locked |
| Hardware | Approved physical dedicated or self-hosted hardware |
| Virtualization | VM, VPS, and VDS infrastructure is not permitted for licensing |
| Memory | Policy wording: 8 GB RAM minimum; 4 GB additional per game instance |
| Memory Speed | Approximately 3000 MHz or faster is recommended |
| Administration | At least 10 active administrators per server |
| Healthy Performance | More than 35 server TPS |
| Degraded Performance | Below 25 server TPS |
| Critical Performance | Below 15 server TPS |
| Maintenance | Regular restarts and responsive administration are expected |
Licensing Readiness Checklist
Use this list to decide if you should apply now or wait.
- Stable Peak-Hour Performance
- Your server stays smooth when full.
- Your restarts do not hit prime time.
- Your update process is repeatable and predictable.
- Admin Coverage Plan
- You can cover your busiest hours.
- You have a defined escalation path for serious incidents.
- You remove staff access fast when roles change.
- Clear Rules And Enforcement
- Rules show in your server messages and Discord.
- Staff follows the same warning ladder.
- Staff logs serious actions.
- Appeal Path
- One place for appeals.
- A simple template players must follow.
- A response timeline your team can meet.
- Clean Naming
- Your server name is readable in the browser.
- Your region and server style are clear.
- Multiple servers follow a simple “#1 / #2” naming pattern.
If you cannot meet these points, run unlicensed, fix operations, then apply.
Squad Dedicated Server Troubleshooting
Follow the checks for your issue in order. After changes, restart where required and test visibility and joining from another network.
| Issue | Step | Check | Action |
|---|---|---|---|
| Server not showing up | 1. Advertising | Internet advertising settings | Set ShouldAdvertise=true and IsLANMatch=false for internet hosting, then restart. |
| Server not showing up | 2. Ports | Game, query, and beacon reachability | Allow the configured ports and required protocols through both the OS firewall and provider firewall or router. Keep RCON restricted to trusted sources. |
| Server not showing up | 3. Bind IP | Interface used on hosts with multiple IPs | If needed, set MULTIHOME to an IP assigned to the intended local interface. Do not use an unassigned public IP or documentation placeholder. |
| Server not showing up | 4. NAT | CGNAT or double NAT | For double NAT, forward ports through both routers. For CGNAT, request a public address or supported inbound mapping from the ISP. |
| Server not showing up | 5. Server application | SteamCMD installation target | Confirm you installed the Squad dedicated server using App ID 403240. |
| Server not showing up | 6. Browser and access | Listing category, filters, and external joins | Check Custom Servers for unlicensed servers and the main Server Browser for licensed servers. Clear restrictive filters and test from another network. |
| Queue disconnects or failed joins | 1. Server load | TPS, CPU-thread usage, memory, and logs | Temporarily lower the player cap and test lighter layers. Consider a faster per-core CPU only if measurements show a CPU bottleneck. |
| Queue disconnects or failed joins | 2. Network quality | Packet loss, jitter, and upload congestion | Use a wired host connection, remove uplink congestion, and investigate routing problems. Bandwidth alone does not establish connection quality. |
| Queue disconnects or failed joins | 3. Maintenance timing | Disconnects coinciding with restarts or updates | Schedule routine maintenance during low-population hours and announce it. Apply urgent fixes outside that window when necessary. |
| Queue disconnects or failed joins | 4. Mods and loading | Errors or stalls during map transitions | Check server and client logs. Test suspect mods individually on a staging server and remove incompatible mods. |
| Queue disconnects or failed joins | 5. Compatibility and authentication | Client/server versions, Workshop files, and authentication errors | Update compatible server and mod files, then retest. Investigate Steam, EOS, or Offworld services when logs indicate an authentication or service problem. |
| Server down or browsing failure | 1. Scope | Whether one server or many are affected | Compare reports across servers and regions. Widespread symptoms suggest a shared problem but do not prove an outage. |
| Server down or browsing failure | 2. Updates | Installed build and updater results | Confirm the expected server build. If an update failed, stop the server, rerun the SteamCMD updater, and check its output. |
| Server down or browsing failure | 3. Firewall rules | Rules after OS or provider changes | Recheck both firewall layers against the configured ports. Restore missing or incorrect rules. |
| Server down or browsing failure | 4. Process health | Crash loops, dependencies, and logs | Confirm the process stays running for at least 10 minutes and resolve logged errors. A running process does not prove players can join. |
| Server down or browsing failure | 5. Remaining causes | Advertising, browser category, bind IP, versions, mods, and service status | Recheck these before reinstalling or attributing the failure to an upstream service. Confirm recovery with an external join test. |
Squad Hosting Options Compared
Compare the actual hardware, network, permissions, and support included in each plan. A game panel can also run on bare metal.
| Hosting option | Useful for | Main limitations to check | Before choosing |
|---|---|---|---|
| Home hosting | Learning, configuration testing, and private events | CGNAT, double NAT, unstable upload, power interruptions, and router restarts | Verify inbound connectivity, test under your expected player load, and account for electricity and equipment costs. |
| Game panel hosting | Quick setup and convenient update, restart, and configuration controls | CPU allocation, shared-resource contention, access restrictions, and provider support scope | Ask about the underlying hardware, allocated resources, available controls, and licensing eligibility. |
| Bare metal hosting | Dedicated resources, OS control, and communities with specific performance needs | Hardware suitability, total cost, and responsibility for maintenance | Test your intended player cap, check applicable Offworld licensing requirements, and confirm who handles updates, backups, monitoring, and security. |
Choose based on tested performance and total operating cost. Hosting type alone does not guarantee stability or licensing approval.
Why RedSwitches Fits Squad Hosting
A successful Squad server setup ends with players joining and performance holding up under load. Correct browser placement, reachable ports, secure admin access, and tested mod compatibility all matter. Once those checks pass, your hardware needs to support the matches you plan to run.
RedSwitches gives you control over that foundation with dedicated bare-metal resources, NVMe storage options, full root access, and DDoS protection. Multiple server locations let you choose a region near your community, while 24/7 infrastructure support provides help when hosting issues arise.
Root access lets you configure Squad, firewall rules, monitoring, and backups around your own operating needs.
Choose your CPU around sustained performance per core, then validate your player cap with real matches. Keep updates predictable and monitor performance as your community grows.
Ready to put the guide into practice? Talk to RedSwitches about your target player count, preferred region, and mod requirements to choose a configuration you can test and build on.
Frequently Asked Questions
Common questions about squad dedicated server setup: windows, linux, ports and licensing.
What Is A Squad Dedicated Server?
How Do I Download The Squad Dedicated Server?
What Are Squad Dedicated Server Requirements For 80 Players?
What Are Squad Dedicated Server Ports?
Why Is Squad Dedicated Server Not Showing Up?
Why Do I Get Squad Dedicated Server Disconnected From Queue?
Can I Run Squad Dedicated Server Linux On A VM?
What Is The Squad Dedicated Server App ID?
What Is The Latest Squad Dedicated Server Version?
Can I Run A Squad Server Without A License?
What TPS Should A Squad Server Maintain?
Hafsa Qadeer
Technical Writer
Hafsa Qadeer is a Technical Content Writer at RedSwitches and a journalist with a background in molecular biology and oncology. She brings research precision to technical writing and SEO strategy, turning complex topics in infrastructure, biotech, and AI into content that informs and engages.
Power Your Next Project With Bare Metal
10 min delivery, zero setup fees, and 24/7/365 human engineers across 20+ global locations.


