reply to Brano
In theory you could for most services. In reality not for IPSec. Also USG doesn't support that. You can either have IPSec terminated on USG or pass-through. Not both at a same time on one interface.