How to allow one way traffic in an IPSEC Tunnel?

Hello,

I have IPSECs tunnels between my company and our customers (Fortinet on both sides).

I create a VPN Tunnel, a Policy and it works fine.

I need to create a tunnel between me and a client but I only want traffic to be allowed in one way : from me to the client. The client shouldn’t be able to contact my network.

It tried putting a deny policy that way before the policy of the tunnel but it doesn’t work.

How should I do ?

Thanks.