1. Bicom Systems
  2. Solution home
  3. SERVERware
  4. HOWTOs SERVERware 5

Installing geoip module on Ubuntu 24.04

If we have a system where sipPROT cannot be started because the GeoIP module is missing, which we can confirm with the following command:


root@sc001mywlpbxcom:/# systemctl status sipprotd.service
× sipprotd.service - sipPROT
     Loaded: loaded (/etc/systemd/system/sipprotd.service; enabled; preset: enabled)
     Active: failed (Result: exit-code) since Tue 2026-09-01 02:17:01 CDT; 6min ago
    Process: 2258945 ExecStartPre=/usr/sbin/modprobe ip_tables (code=exited, status=0/SUCCESS)
    Process: 2258947 ExecStartPre=/usr/sbin/modprobe br_netfilter (code=exited, status=0/SUCCESS)
    Process: 2258949 ExecStartPre=/usr/sbin/modprobe -b xt_geoip (code=exited, status=1/FAILURE)
        CPU: 9ms

Sep 01 02:17:01 sc001mywlpbxcom systemd[1]: Starting sipprotd.service - sipPROT...
Sep 01 02:17:01 sc001mywlpbxcom modprobe[2258949]: modprobe: FATAL: Module xt_geoip not found in directory /lib/modules/6.17.0-1022-azure
Sep 01 02:17:01 sc001mywlpbxcom systemd[1]: sipprotd.service: Control process exited, code=exited, status=1/FAILURE
Sep 01 02:17:01 sc001mywlpbxcom systemd[1]: sipprotd.service: Failed with result 'exit-code'.
Sep 01 02:17:01 sc001mywlpbxcom systemd[1]: Failed to start sipprotd.service - sipPROT.

If the version of Ubuntu is 24.04 here is the guide which should be followed:


Step 1: Install System Dependencies and DKMS Module

(Note: iptables-dev from older Ubuntu releases is replaced by libxtables-dev on 24.04)

Bash
apt-get update && apt-get install -y gcc g++ make automake unzip zip xz-utils linux-headers-$(uname -r) libxtables-dev libiptc-dev cpanminus dkms xtables-addons-dkms


Step 2: Install Required Perl Modules for GeoIP

(Uses cpanm for a faster installation of the Perl dependencies needed by GeoIP processing scripts)

Bash
cpanm Text::CSV Text::CSV_XS Net::CIDR::Lite


Step 3: Load the xt_geoip Kernel Module

Update module dependencies and load xt_geoip into the running kernel:

Bash
depmod -a
modprobe xt_geoip

Verification (Optional):

lsmod | grep xt_geoip

(The output should list the xt_geoip line, confirming it is active).


Step 4: Restart and Verify sipprotd Service



systemctl restart sipprotd.service
systemctl status sipprotd.service


To confirm whether sipPROT is working fine use command:


root@sc001mywlpbxcom:~# systemctl status sipprotd.service
● sipprotd.service - sipPROT
Loaded: loaded (/etc/systemd/system/sipprotd.service; enabled; preset: enabled)
Active: active (running) since Tue 2026-09-01 02:49:00 CDT; 5s ago
Process: 2264992 ExecStartPre=/usr/sbin/modprobe ip_tables (code=exited, status=0/SUCCESS)
Process: 2264994 ExecStartPre=/usr/sbin/modprobe br_netfilter (code=exited, status=0/SUCCESS)
Process: 2264996 ExecStartPre=/usr/sbin/modprobe -b xt_geoip (code=exited, status=0/SUCCESS)
Process: 2264998 ExecStartPre=/usr/bin/bash -c echo 1 > /proc/sys/net/bridge/bridge-nf-filter-pppoe-tagged (code=exited, status=0/SUCCESS)
Process: 2265000 ExecStartPre=/usr/bin/bash -c echo 1 > /proc/sys/net/bridge/bridge-nf-filter-vlan-tagged (code=exited, status=0/SUCCESS)
Process: 2265003 ExecStartPost=/bin/sh -c umask 022; pgrep sipprotd > /var/run/sipprotd.pid (code=exited, status=0/SUCCESS)
Main PID: 2265002 (sipprotd)
Tasks: 10 (limit: 19150)
Memory: 23.9M (peak: 27.0M)
CPU: 618ms
CGroup: /system.slice/sipprotd.service
└─2265002 /usr/bin/sipprotd --config /opt/sipprot/conf/sipprot.conf --log syslog://

Sep 01 02:49:00 sc001mywlpbxcom /usr/bin/sipprotd[2265002]: [ info ] Loading firewall rules ...
Sep 01 02:49:00 sc001mywlpbxcom /usr/bin/sipprotd[2265002]: [ info ] - setting up TRUSTED DOMAINS protection
Sep 01 02:49:01 sc001mywlpbxcom /usr/bin/sipprotd[2265002]: [ info ] - setting up ALLOWLIST protection
Sep 01 02:49:01 sc001mywlpbxcom /usr/bin/sipprotd[2265002]: [ info ] - setting up DENYLIST protection
Sep 01 02:49:01 sc001mywlpbxcom /usr/bin/sipprotd[2265002]: [ info ] - setting up DENYLIST6 IPv6 protection
Sep 01 02:49:01 sc001mywlpbxcom /usr/bin/sipprotd[2265002]: [ info ] - setting up DYN_DENYLIST protection
Sep 01 02:49:01 sc001mywlpbxcom /usr/bin/sipprotd[2265002]: [ info ] - setting up DYN_DENYLIST6 IPv6 protection
Sep 01 02:49:01 sc001mywlpbxcom /usr/bin/sipprotd[2265002]: [ info ] - setting up SIP protection
Sep 01 02:49:02 sc001mywlpbxcom /usr/bin/sipprotd[2265002]: [ info ] - setting up SIP IPv6 protection
Sep 01 02:49:02 sc001mywlpbxcom /usr/bin/sipprotd[2265002]: [ info ] - setting up TFTP protection