iptables -A INPUT -i eth0 -p tcp --dport 22 -m mac --mac-source 00:0B:DB:45:56:42 -s 192.168.1.1 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp -m tcp --dport 22 -j DROP
Should do it ...tweak for mac address and ip. If your default input policy is already drop you won't need to set the second rule...
Beware, MAC's are trivial to change ;)