Creating VLANs as links on a tagged port for security

Where Multi-VRF is used, for example, in an enterprise data center, trusted servers or devices should be allowed to communicate directly, and untrusted ones should not be allowed to communicate directly at all. This optional task configures tagged Layer 3 interfaces to support secure VRF instances.
  1. In global configuration mode, create a VLAN.
    device(config)# vlan 10
    device(config-vlan-10)# 
  2. Use the tagged command to identify the interface as secure.
    device(config-vlan-10)# tagged e 1/1/1
  3. Repeat the previous step on the corresponding interface on the peer device.