Hi there,
Once you configure a Layer2 sub-interface you are creating a trunk link and 802.1q will be enabled, using the 'tag' value as the VLAN ID on the encapsulated frame.
An access port if you think about doesn't really need a VLAN tag, as it is never imposed on the frame, they arrive and leave untagged. The VLAN tag/ ID is there purely to identify which virtual-bridge the frames belong to.
The object created under Network -> Interfaces -> VLAN is not a subinterface. I see you confusion as it prepends a digit to the interface name. The interface here is a SVI/ IRB . If you have configured your firewall interfaces all as Layer2, then yes you will need these for inter-VLAN routing. You can have a mix of routed Layer 3 interfaces (dedicated or subinterface) and VLAN interfaces for inter-VLAN routing, depending on your topology.
cheers,
Seb.
... View more