Multiple inputs using the same port

I would suggest that getting firewalls changed would be a nicer and more complete solution. There will be no way to differentiate the logs coming in so I don't think what you want to do will work. You could try setting both to use SSL but again, no way for logstash to tell if it is receiving HTTP or beat traffic.