Fiveguard Configuration
This documentation was made by the Fiveguard staff to help both users who already have their own build (even if they believe it is “optimal”) and those who have just purchased the service. Our tutorial is compatible with any framework and any server type (RP, PvP, and more).
Let's start creating your server config. Click the Config category on the right and start to import our pre-made config.
Import Config
Log into Fiveguard, click Config next to your licence, then press Import Config at the top‑right and paste this code HCLC-NI60.
Once entered, set the logs and your framework than save the config.
Open your txAdmin and click Resources on the left, then copy the entire page into a .txt file.
Open any AI model and provide this prompt with the .txt attached:
I have a list of resources from my txAdmin server (below). Return only the folder names, one per line, preserving hyphens (-) and underscores (_) exactly. Do not add authors, versions, or other information. Do not skip any lines.
Put the list of resources AI has provided you here:
- In EntityDetection > Objects A I Resource Whitelist
- In Basic > Anti Spawn Props By Unauthorized Resources Mode2 Table
Save the config, restart the server, then run fg objects-ai install and fg safe-events install, then restart again.
How to Set Up Logs
Go to the Logs category on your online dashboard and configure the webhooks.
To obtain the webhooks on your Discord server:
- Create a new text channel
- Right‑click > Edit Channel
- Integrations > Webhooks
- Select the webhook > Copy Webhook URL
- Paste the URL into the chosen log
Optional Settings
We recommend enabling:
- Category Client: Anti Freecam (in Anti Freecam Allow Coords, enter the freecam coordinates).
- Category Vehicle: Anti Vehicle Modifier (in Anti Vehicle Modifier Mechanic Coords, enter the mechanic coordinates).
Staff accessing via txAdmin will be banned if they try to repair their vehicle with the txAdmin menu.
Objects-AI Resource Whitelist
Inside the table Objects A I Resource Whitelist you must add all the resources on your server that spawn props, vehicles, or any models to prevent them from being removed by the anti-cheat during the automatic cleanup (about every 15 minutes).
Anti Attach Entity To Player Models White List
If some objects keep disappearing even after you whitelisted their resources in Objects-AI Resource Whitelist, those specific models have to be added here.
- Open the txAdmin console and type
fg logs delobj. While running the script, note the models value that appears (the numeric hash model) and insert that number (for example-1111111) into Anti Attach Entity To Player Models White List. - Use the freecam function from the in-game admin panel (command
/fgm) to capture the model hash and add it to the same white list.
Entity Detection List
Are you receiving a ban like this?
Ban Reason: Blacklisted Entity detected, model 1684083350
Additional Info: Config Option: EntityDetection.EntityDetectionBan
Remove the hash number 1684083350 from your Entity Detection List.
If you cannot locate it by hash, you need the specific model name. Search for GTA Forge, enter the hash, and you will obtain the correct name (e.g. S_M_M_MovAlien_01). Find that name in the list and delete it.
Props Disappearing/False Ban
Do you still see props disappearing even after adding them to Objects-AI Resource Whitelist and Anti Attach Entity To Player Models White List? Then the issue is related to Anti Weird Objects Spawn; disable this option.
This option can rarely cause issues for some scripts, so be careful!
Also check if the vehicle is not among the blacklisted vehicles in the Blacklist category in Blacklisted Vehicles
Gas Station Explosions Loop
Do you see gas stations continuously exploding in a loop? Install this add-on in your resources: https://github.com/OffSey/addon. Inside, you will find a "Stream" folder with the fixed .ytyp file. You can either import the entire add-on or extract only the .ytyp file and put it in any stream folder.
If the problem persist, disable the Anti Weird Objects Spawn from EntityDetection category.
Explosions Removed/False Ban
Just check the logs for the explosion ID, and if the explosion has the phrase "AI Explosion Detection", you must add the explosion ID to the AI Explosion Detection Whitelist. If it does not include this phrase, look for the explosion ID in the Explosions List and format the explosion as follows:
- log enabled
- ban disabled
- block disabled
- Exclude From Global Mass Explosion enabled
Particles Ban
Receiving a false ban for particle usage? Simply copy the particle hash and add it to the Particles Ignore List.
SafeEvents
Are modders managing to use your server triggers? We recommend modifying your scripts to move all triggers server-side to make them harder for cheaters to execute, but Fiveguard also offers great protection for those who cannot do so
Go to the "SafeEvents" category and enable:
Safe Events enabled
If you have installed our pre-made configuration this is already enabled; just save the config and restart the server, wait for Fiveguard to load, then run fg safe-events install in the console and restart again.
Extended Security to protect Client side
Are cheaters still able to trigger actions like opening vehicle trunks or stealing items from player inventories? Do the following:
Extended Security enabled
Extended Security Mode set to "strict"
If you installed our pre-made configuration this is already enabled; just save the config and restart the server, wait for Fiveguard to load, then run fg safe-events install in the console and restart again.
Safe Events False Ban
Receiving false bans related to the Safe Events protection?
Ensure the protection is installed on all scripts by running fg safe-events install. If a script calls a protected event but isn't covered by SafeEvents, it will lead to false bans. If the issue persists, check the ban logs and follow this guide:
- If in "Additional Info" you see SafeEvents.SafeEvents, the token (e.g.
resourcename:ServerCallback) should be added to the Ignore Events List. - If in "Additional Info" you see SafeEvents.ExtendedSecurity, the token (e.g.
resourcename:PeriodicalPlayerStatusCheck) should be added to the Ignore Security Events List.
Be careful which triggers you whitelist; whitelisting something like ox_inventory:OpenInventory is pointless if cheaters can still open inventories. Ensure all resources are protected by running fg safe-events install first.
Web Permissions via Permissions category
Want to add permissions via the website?
Go to the "Permissions" category and do the following:
- Alternative Permissions Check enabled
- Alternative Permissions – click Add Row
- identifier can be:
- steam
- discord
- license
- license2
- fivem
- live
- xbl
- ip
We personally recommend using discord:1111111111111111111 or license:
To ensure they're read by the anticheat, go to the Basic category and do:
- Required Identifiers enabled
- Required Identifiers Types – enable the identifier you need
If you have installed our pre-made configuration this is already enabled.
Ace Permissions
Can't give permissions via website but via setgroup?
Go to the Permissions category and disable Alternative Permissions Check.
You can set setgroups enabling entire permission categories:
- AdminMenu
- Client
- Weapon
- Vehicle
- Blacklist
- Misc
Or individual permissions listed here: Official Docs
If you're on ESX, Ace Permissions only work if you enable Auto Permission Group Setter in the ESX category via website.
Package Addon
Install this addon and add it as a resource on your server (DO NOT place it inside your Fiveguard folder).
Open the addon config.lua and do the following:
- line 5: put a webhook
- line 32: put
false - line 63: add all the coords of your server where the vehicles are generated with the native "CreateVehicle" (like some dealerships)
- line 79: put
true - line 80: add all resources that spawns vehicles
- line 121: Use the default template to use the temporary permissions system. For the bypasses list click here.
After doing all this, restart the server and run this command fgAddon bypass-native install
If you encounter permission issues (if you are using the default ones like tx/framework or others) add this line in your server.cfg add_ace resource.addon command allow
Anti Spoof
Do you want to enhance your anti-spoof protection security?
It depends on the type of spoof. The best method is:
- Enable every ban type available on the anti-cheat dashboard (including IP bans – note that this may cause false bans if your server uses a reverse proxy) and also enable anti-VPN.
- Enable the whitelist in txAdmin using the Discord role method.
- Activate a verification bot on your Discord server (a free option is My Bot). Clicking the Verify button grants the role configured as whitelisted to access the server (see step 2).
- In your Discord server settings, enable the Community option.
-
Go to Security setup > Direct Message and Spam Protection and set the Verification Level to Highest.
(This requires users to have a valid phone number linked to their account to receive the Verified role and access the server, making spoofing much more difficult.)
As for the rest, Fiveguard includes multiple levels of token bans, so you are already well protected on that front. But by following these steps, you’ll be much more secure.
Fix False Bans/Detections
If you installed our pre-made config this guide collects possible false bans/detections for that specific setup, and it's also helpful for custom configurations.
False BAN Category SafeEvents
If you see a false ban and in the Additional Info you read SafeEvents, add the token to the whitelist as below:
- SafeEvents.SafeEvents – add to Ignore Events List
- SafeEvents.ExtendedSecurity – add to Ignore Security Events List
False BAN Category Basic
If you see a false ban and in the Additional Info you read Basic.AntiSpawnPropsByUnauthorizedResources, do this:
- Anti Spawn Props By Unauthorized Resources (bottom of page) – add the resource to the Anti Spawn Props By Unauthorized Resources Mode2 Table
See props/vehicles disappearing Category EntityDetection
- Add the resource to the Objects A I Resource Whitelist
- If still not fixed, you may have issues with "Anti Attach Entity To Player": either disable it or in txAdmin run
fg logs delobjto see the deleted model and add it to Anti Attach Entity To Player Models White List. - If still not working, disable Anti Weird Objects Spawn; it often causes issues.
How to Resolve Some Common Errors
Common errors:
-
[fiveguard] Error: y7aeBP- Install the latest artifacts and reinstall the anticheat (back up the bans.json file or you will lose all your bans).
- Remember to remove any other anticheat folders or Fiveguard won’t start. On some anticheats it is possible to whitelist Fiveguard so that it does not modify Fiveguard files.
-
[fiveguard] Error: could not establish connection (1), error: 0
[fiveguard] Error: You need to whitelist *.fiveguard.net, auth.fiveguard.net, and api.fiveguard.net in your DDOS protectionYou need to open port 2096 in your anti-DDoS system (discuss this with your host) and also on your local firewall.
-
Windows: run CMD as administrator and paste:
netsh advfirewall firewall add rule name="Port 2096 (TCP)" dir=in action=allow protocol=TCP localport=2096 -
Linux:
- For UFW (Ubuntu, Debian):
sudo ufw allow 2096/tcp - For Firewalld (CentOS, RHEL, Fedora):
sudo firewall-cmd --permanent --add-port=2096/tcp && sudo firewall-cmd --reload - For iptables:
sudo iptables -A INPUT -p tcp --dport 2096 -j ACCEPT
- For UFW (Ubuntu, Debian):
-
Windows: run CMD as administrator and paste:
-
The /fgm command is not working
- First of all try to open it using
/fgmenu, if still doesn't work disable Windows Defender on your VPS or whitelist the Fiveguard resource.
- First of all try to open it using
-
[fiveguard-Admin-Panel] Unauthorized Accessor the "Web Panel" is not showing up- To solve the problem you need to
open port 2096(as mentioned above), if still doesn't work disable Windows Defender on your VPS or whitelist the Fiveguard resource.
- To solve the problem you need to
-
Error: (0xE4) Report This To Fiveguard Team- The
fxmanifestis modified (probably another anticheat is altering the fxmanifest of the resource, preventing it from starting correctly). To fix this, reinstall Fiveguard while saving thebans.jsonfile and whitelist Fiveguard on the other anticheat so that it does not modify Fiveguard files.
- The
-
Error: (0xP1) Report This To Fiveguard Team- Make sure you have only one Fiveguard resource on your server (no duplicates) and ensure that the events executed by the anticheat are not being blocked by the server.
-
[fiveguard] Error: 403 forbidden- Open a ticket on our Discord attaching your VPS IP so we can verify your IP.
-
[fiveguard] Error: SyPz2c- Install node.js from this link on your VPS, then disable Windows Defender (or any other type of antivirus from your VPS) and reinstall the Fiveguard folder (remember to backup the
bans.jsonfile and put it back in the new folder or you will lose all the bans). Finally, reinstall the artifacts from the official website..
- Install node.js from this link on your VPS, then disable Windows Defender (or any other type of antivirus from your VPS) and reinstall the Fiveguard folder (remember to backup the
-
“There is a cheater that ban all my players via Fiveguard also if he has not any permissions”
You almost certainly have a backdoor in your scripts causing this. Check your leaked scripts/MLOs and then:
- Remove any leaked scripts or MLOs.
- Open every resource folder in Visual Studio Code and search for suspicious code:
- Search for
const _ = Buffer.fromin all your resources (not all matches are malicious—be sure before deleting). - Search for
PerformHttpRequest. - Search for
PerformHttpReques(typo variant). - Inspect all
htmlfolders for JavaScript files that could grant hacker permissions.
Credits
This project was made possible with the help of the Fiveguard support team.
I would like to thank xinodev for support in fixing common errors and to Jeakels and OffSey for the creation of the addon available free of charge to all Fiveguard customers. I also thank the Arabic customer support team for providing the complete list of blacklisted names to prevent XSS/CSS injections.
Website, guide and setup created by gabjeksuper