Sure, I have seen a lot of vSAN environments implementing firewalls, provided these are configured properly they should have no negative impact on the performance/operation of the cluster.
The main points are to ensure any firewalls implemented do not block necessary traffic:
Ensure the relevant necessary ESXi host ports are open:
And the ports between ESXi and vCenter:
Provided the relevant ports that vSAN uses are open, vSAN clustering will function normally:
(Note: these listed are default ports so if using non-default e.g. for 'vSAN Clustering Service' then obviously open the ones used)
List of ports for other VMware products and features that may or may not be used in the environment:
Hope this helps.