No 802.1x at all. VLANs are 802.1q. 1x is Authentication. Create a bridge interface for each VLAN that is supposed to host jails or VMs and then explicitly assign the jails to the correct bridge.
Edit, to be a bit more explicit:
VNET Jails on <ANYTHING> means a bridge on that <ANYTHING>. A bridge on the LAGG and VLANs on the LAGG are mutually exclusive.
You need to reboot with all jails set to "off", then create all your VLANs and bridges as desired, then RECONFIGURE all your jails to us a VLAN instead of the LAGG directly.
OK so it is either all LAN or all VLAN?!
You can always run untagged (a LAN as you stated) on one interface and VLANs on another interface. But don't mix.