solução encontrada:
 export const corsOptions = (
  req: Request,
  res: Response,
  next: NextFunction,
) => {
  const allowedOrigins = [
    dominio',
  ];
  const allowedIps = ['34.193.116.226'];
  const origin = req.headers.origin;
  console.log(origin);
  const requestIp = req.clientIp;
  console.log(requestIp);
  if (
    (origin && allowedOrigins.includes(origin)) ||
    allowedIps.includes(requestIp)
  ) {
    next();
  } else {
    res.status(403).send('Not allowed by CORS');
  }
};