I assume you know that there is a difference to the interface listened on and what access is allowed by firewall (see [Solved] 19.07.4 SSH interface "unspecified" by default)
Well if you want to do it on interface level you would need to create two LAN interfaces (one assigned to LAN and one for Wifi) like it is done with a Guest Wifi but then you would need to route between the two (performance?) if you want to use devices in your wired LAN from your Wifi.
Or you would need to do it on a IP level with the firewall and exclude a certain range from the DHCP pool. But that would only give you limited safety.