Under normal circumstances you don’t need to check the “Tagged” checkbox. So let’s assume the Ethernet ports are not tagged.
If you’ve assigned port 1 to X1 and connected your switch to port 1, then all devices connected to the switch will be on the X1 VLAN as the router sees it. Let’s further assume that you’ve configured that X1 should be tunneled through a VPN, then all devices connected to the switch will be tunneled through the VPN.
If you’ve left other Ethernet ports on LAN, then devices connected to these ports on the router will be on LAN, and will not be going through the VPN (if LAN is not configured to go through VPN).