A user reaches the login flow from a visitor address identified by the site.
FluentAuth uses the visitor IP, with trusted proxies configured where required.
The configured network restriction determines whether this role may continue from that address.
An allowed network does not replace the user’s required second factor.
