Go to AWS WAF and Shield Service to the ACLs option:
The client should have ACLs defined inside AWS.