Technically speaking you can, however, it would not be recommended, and it would add complexity to your design. I have seen it once (or maybe twice) with an ASA device where it was behind an edge firewall, and it was only used to terminate AnyConnect VPN connections. Post VPN connections, all the traffic from the ASA was routed back to the edge firewall that was doing all the routing and security policies. Is that something similar to what you would like to do?