Root dn Authentication question for OpenLDAP

1. Can we restrict binding to the root dn so that it is only allowed from a specific ip address (or DNS name)?
2. If the answer to number 1 is no then is there any support for black listisng an ip address if it tries to bind to the root dn and it fails 3 times in a row?