Is it possible to apply firewall on LAN to LAN packets with just PfSense and a layer 2 switch?

Is it possible to apply firewall rules on LAN to LAN packets? Imagine the following architecture: To get a valid IP, the clients must authenticate to PfSense LAN network using 802.1x against the pfSense’s radius server. After that all packets sent between Client1 and Client2 will be managed and filtered by PfSense firewall. Is this…