It's been a while since this post received any responses, but I'd like to contribute something valuable to the discussion.
- Tagged frames keep their VLAN ID as they enter a trunk port, and the switch forwards them only if that VLAN is allowed on that port.
- If the VLAN isn’t allowed, the frame is dropped; if it is allowed, the switch forwards it to ports that are members of the same VLAN.
- Access ports only belong to a single VLAN and remove the tag before sending the frame out.
https://community.cisco.com/t5/networking-knowledge-base/vlans/ta-p/3114286
https://pingmynetwork.com/network/concepts/vlan-fundamentals