Yep, at a few layers.

My favorite is to pass the buck to the netwokr admin and have him restrict access based on IP through thr firewall. Otherwise you could do it in 9i (I think 8i as well)