(MAKE SURE YOU HAVE PEF/PEFNG INSTALLED)
Yes, you can apply firewall policies to the network interfaces (physical or VLAN). You can do this on the GUI at Configuration/Netowrk/Ports menu.
Create your firewall policies first and simply apply it to the interface and it should do the job.
**IF U JUST WANT TO ENABLE FIREWALL ON PORT/VLAN - JUST ADD ACL PROFILE to your VLAN/PORT**
You can if you are using different vlans for each tunnel. You can apply the aaa profile right on the vlan itself.