A few lines in server.cfg shut doors that cheaters use every day: spawning objects, grabbing other players’ cars, faking game events and loading modified game files. They cost nothing. Some of them break scripts, so test them on a copy of your server first. This guide explains each setting in plain words and says what it can break.
In short: the settings that matter
- sv_entityLockdown stops players’ games from creating things on their own.
- sv_filterRequestControl stops players from taking over cars and objects that belong to someone else.
- block_net_game_event drops chosen game actions before they reach other players.
- sv_pureLevel blocks modified game files.
- sv_enableNetworkedSounds and sv_enableNetworkedPhoneExplosions close two routes the FiveM docs say are abused.
- rcon_password and sv_scriptHookAllowed keep remote console and Script Hook off.
Test on a copy of your server first
Set up a test server with the same resources as your live one. Change one setting at a time. Then have staff play normally for an hour: jobs, garages, car dealers, phones, emotes with props, anything that spawns something. Keep the server console open and note every error.
Entity lockdown and request control filtering are OneSync features. Make sure onesync is set to on before you test them.
Entity lockdown
By default, any player’s game can create entities: vehicles, peds and objects. Spawn menus rely on this. sv_entityLockdown limits it. The default mode is inactive, and the FiveM docs list these modes:
- inactive: clients can create any entity they want.
- relaxed: entities that client scripts create are blocked.
- strict: clients can’t create entities at all.
- full: also disables dummy object creation. This mode exists only on FiveM for GTA V Enhanced.
Relaxed is the practical start. It blocks the spawning that scripts and menus do, while the game’s own traffic and pedestrians keep working. Any of your resources that spawn vehicles or props from client code will stop working until your developer moves that spawning to the server. On Enhanced, relaxed also changes when population can spawn, so test traffic there too.
Strict blocks everything clients create. Test it carefully before going live. You can also apply lockdown per routing bucket with the SetRoutingBucketEntityLockdownMode native. That lets you run strict in a PvP arena bucket while the open world stays on relaxed.
Request control filtering
In GTA, a player’s game can ask for control of an entity someone else owns. Mod menus abuse this to grab other players’ vehicles. sv_filterRequestControl blocks those requests. It is off by default. The modes are:
- 0: off.
- 1: blocks requests for vehicles with a player inside, once they count as settled.
- 2: blocks requests for all player-controlled entities.
- 3: also blocks requests for settled entities that no player controls.
- 4: never routes the request at all.
- -1: works like 2 and prints a warning in the console.
Every mode except 0 also blocks requests across routing buckets. For modes 1 and 3, sv_filterRequestControlSettleTimer sets how long after creation an entity still accepts control requests. After that it counts as settled. The default is 30000 milliseconds. Start at 1 or 2, then check tow, impound and mechanic scripts before going higher.
Blocking game events cheaters use
Players’ games tell each other about actions through net game events. block_net_game_event adds one of them to the server’s blocked list. The docs’ own example is block_net_game_event "FIRE_EVENT". The names come from the Net Game Events list in the FiveM docs.
A block applies to everyone, honest players included. Block only events your server never needs. Before copying the fire example, check whether any weapon, job or script on your server relies on fire.
Explosion spam is the classic case. Blocking EXPLOSION_EVENT would stop it, but it would also block explosions honest players cause. Most servers can’t give that up. The Cfx.re cookbook shows a different route on OneSync: a server handler for explosionEvent. It shows who sent each explosion, its type, position and damage scale. CancelEvent stops it from reaching other players. Your developer can use this to cap explosions per player and block them in safe zones.
Pure level
sv_pureLevel blocks players who joined with modified game files. Level 1 blocks all modified client files except audio files and known graphics mods. Level 2 blocks all modified client files.
Level 1 suits most communities. Level 2 also stops players from using sound packs and graphics mods, so tell them before you switch. On GTA V Enhanced, pure mode is always on and can’t be turned off.
Networked sounds and phone explosions
sv_enableNetworkedSounds is true by default. Setting it to false stops game sounds from being routed through the server, a route the docs say is commonly abused. A script that plays game sounds for nearby players may need another approach.
sv_enableNetworkedPhoneExplosions is false by default. The docs warn that turning it on also gives malicious players a tool. Leave it off unless a resource truly needs it.
sv_enableNetworkedScriptEntityStates is true by default, and the docs describe it the same way. Turn it off only after testing, since some scripts may rely on that route.
RCON and Script Hook
If rcon_password is unset, RCON is disabled. Leave it that way unless you really use RCON. FXServer RCON runs over UDP. On GTA V Enhanced, remote console is off by default.
sv_scriptHookAllowed is false by default. The docs say turning it on is not recommended because it makes the server vulnerable. Keep it false.
Baseline config and what it breaks
- onesync on: required for lockdown and request filtering.
- sv_entityLockdown relaxed: breaks client-side spawning in your scripts until it moves to the server.
- sv_filterRequestControl 2: can break tow, impound or vehicle control scripts.
- sv_pureLevel 1: blocks modified client files, while audio and known graphics mods still work.
- sv_enableNetworkedSounds false: scripts that sync game sounds between players.
- sv_enableNetworkedPhoneExplosions false: nothing for most servers, since this is already the default.
- sv_scriptHookAllowed false: nothing, it is the default.
- rcon_password left unset: RCON tools stop working.
Lock down admin commands with ACE permissions
FAQ
Will these settings stop all cheaters?
They close network tricks. They can’t see an aimbot, godmode or an executor running inside a player’s game, and they don’t protect server events your resources register.
Secure your server events against fake triggers
Which setting breaks the most scripts?
Entity lockdown, by far. Roll it out last, on a test server, with a developer ready to move spawning code to the server.
Do I need these on GTA V Enhanced?
Yes, with two changes. Pure mode is always on there, and entity lockdown gains the full mode.
Daddy Shield covers the part these convars can’t reach: what happens inside the player’s game. It has 40+ protections, a screenshot on every ban and no database to set up. Like these settings, every protection can start on watch only while you test.