OK i had a quick look - i think you havve a basic misunderstanding - yes ports can be dual mode (tagged and untagged traffic) but in your case for the ESXI servers they will be trunk ports - untagged traffic is simply traffic that comes from a device that does not understand VLANs and the switch port it is connected to (or the device such as the Unifi) is in charge of adding the tag - so in other words Tagged and Untagged has nothing to do with the packet on the wire it has to do with what the device at the end will do with it.Does anyone get a moment to look this over and make sure this will work before I send myself down a 2-3 hour rabbit hole again?
If you enable VLANs on the switch all packets that traverse the switch will have VLAN tags on them - some of them might be for the default VLAN for the switch - and when they get to an egress port - the VLAN tag will be stripped.
On a device such as a Unifi - assuming it supports both tagged and untagged clients - then the port the wireless clients connect to will have a PVID - any clients that do not put a tag on their packets (most PCs, phones etc) will have the PVID given to the packet
Craig