Access by IP address or subnet in ProFTPd is very easily restricted.
In the main ProFTPd configuration file, we simply specify which users should have restricted access by IP address:
<Limit LOGIN>
AllowUser ixnfo.com@192.168.1.0/24
DenyUser ixnfo.com
AllowAll
</Limit>
AllowUser specifies where the user ixnfo.com can connect from, DenyUser is needed to block all other IP addresses for this user, AllowAll – allows all other users not specified in AllowUser to connect from anywhere.
But if possible, it is better to restrict access through a firewall rather than through the ProFTPd configuration.
See also my articles:
Configuring FTPS in ProFTPd
Configuring ProFTPd with virtual users in a file
