In some cases you can and can't. It depends where the DHCP server is.
If the DHCP server is configured as a IP helper and resides on a different vlan , there are some nasty hidden firewall rules that will still allow the trafic ( eg: Wireless firewall , GP 'firewall' )
I find that very annoying.
Also the MX firewall won't block trafic that has a destination in the autoVPN tunnel , you would need to use the S2S firewall. You can get confused real quick