Protecting REST Admin API (admin-cli)?

I would like to limit the builtin admin-cli client to localhost and a few LAN IPs, since it has realm admin capacity and would be dangerous to be exposed to the whole world. How can this be done? Thank you!