I'm not telling you it's malpractice to use it that way, but we wouldn't.
Why?
I'm not tptacek, but note that IP addresses are not exactly cryptographically secured. If you only restrict access by IP address, you tend to lose your whole intranet as soon as one host falls.