Do you have any resources on how to allow ssh access from certain IP ranges? I can't find anything useful on this topic.
If you're using public/private keys you can use the "from" option for the keys. But it's not fool proof.
If you want to get clever then you can enable port knocking but my personal preference is just good old fashioned whitelist of IPs with fail2ban running ready to auto-blacklist any of those IPs that have too many failed login attempts in a given period of time.