diff --git a/docs/ipsets.xml b/docs/ipsets.xml index f2d1bff61..4640fc04f 100644 --- a/docs/ipsets.xml +++ b/docs/ipsets.xml @@ -24,6 +24,8 @@ 2010 + 2015 + Thomas M. Eastep @@ -170,6 +172,12 @@ ACCEPT net:+sshok $FW tcp 22 url="manpages/shorewall.conf.html">shorewall.conf(5), then only ipv4 ipsets are saved. Both features require ipset version 5 or later. + + Although Shorewall can save the definition of your ipsets and + restore them when Shorewall starts, in most cases you must use the ipset + utility to initially create and load your ipsets. The exception is that + Shorewall will automatically create an empty iphash ipset to back each + dynamic zone.