Scenario: Same users can connect from two different network segments to a ssh host. But they should not be able to use interactive ssh session when connecting from one (it's actually long-distance tunnels), only chrooted sftp should be allowed.
How can it be achieved? Is this achievable by sshd's settings? Or by tcp wrapper (libwrap) + sshd?