granting/denying access based on client ip address

hi , everybody

IS there a way to grant/deny access to your ldapserver

based on client ip address??
- ACL 
I wanted to block machine from
accessing the ldap server:

access to *  
 by addr="" none

But I still could retrieve information by running
ldapsearch on  machine , by using the
rootdn to bind to the ldap server.

Let say I only wanted machines and to be able to access the ldapserver,
all other machines should be denied access.

What are the ACL?

Let say i wanted to block network,allow
access for network 

what are the ACL?

- TCPwrappers:
a quote:"TCP-Wrappers is another security enhancement
package. The theory is that you take programs being
run under inetd (see /etc/inetd.conf) and before you
run the program to do the real work (ftpd, telnetd,
etc...), you first run the connection attempt through
a package that checks to see if the IP address of the
source packet is coming from a host known to be either
good or bad (you may filter connection attempts by
source host name, domain name, raw IP address, port
they are attempting to connect to; and either allow
known good connections through thus refusing unknown
connections, or accept all connections except those
known to be bad)." 

TCPwrappper is not such a good idea since it means
that you don't have a standalone slapd daemon , thus 
performance goes down.

thanks in advance.

