ASA supports shaping/policing and one priority queue (per interface).
http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_qos.html
This document describes policing for l2l tunnel on ASA.
The following example builds on the configuration developed in the previous section. As in the previous example, there are two named class-maps: tcp_traffic and TG1-voice.
hostname(config)# class-map TG1-best-effort
hostname(config-cmap)# match tunnel-group Tunnel-Group-1
hostname(config-cmap)# match flow ip destination-address