diff --git a/docs/ipsets.xml b/docs/ipsets.xml
index 8e997242a..c94fb1032 100644
--- a/docs/ipsets.xml
+++ b/docs/ipsets.xml
@@ -95,8 +95,8 @@
- They must be composed of letters, digits or underscores
- ("_").
+ They must be composed of letters, digits, dashes ("-") or
+ underscores ("_").
@@ -128,6 +128,11 @@ ACCEPT net:+sshok $FW tcp 22
blacklist file, you can coerce the rule into matching the destination IP
address rather than the source.
+ Beginning with Shorewall 4.4.14, multiple source or destination
+ matches may be specified by placing multiple set names in '+[...]' (e.g.,
+ +[myset,myotherset]). When so inclosed, the set names need not be prefixed
+ with a plus sign.
+
Shorewall can save/restore your ipset contents with certain
restrictions: