according to my documentation, this is what it says about security:
Security
If you want to restrict one or more users to only be able to connect from a specified IP address, or if you want to keep all IP addresses except your own from logging onto your server, you can do that from the "Security" tab.
Right-click inside the ip access list to bring up a menu with the availible actions.
When you add a new access rule you must specify which user and what IP adress the rule should apply to. The IP address field accepts full IP addresss and wildcards. You also have to specify whether the rule should allow or disallow the user from logging on to your server.
and it also shows this picture:

Should I enter that to all users?