The VLAN mode documentation for the CSS106 and at least CSS326 are not consistent. Specifically on the CSS106 it says vlan mode applies to ingress port, but the CSS326 it says the vlan mode is relevant to egress ports. The CSS106 has a separate VLAN header setting but it isn't clear to me if this is applied on ingress or egress. Also different is the documentation for the vlan mode disabled.
SwOS doesn't seem to have a global setting to turn vlan-aware mode on and off, unlike the ROS bridge does with the vlan-filtering option. Instead it is configured per port.
The reason I was looking at this was because I just switched to ATT Fiber 300 (from Spectrum cable) and wanted to put a tap to watch traffic on the "WAN" side of the router (between my home router and the ATT BGW320 LAN) but I don't want RSTP or LLDP stuff being tranmitted from the switch ports connected to the ISP side. I have the ATT BGW320-505 in passthrough mode, but that's a "hack" which evidently masquerades all traffic to the BGW320's LAN, and then reapplies source NAT to make it appear to the home router as if it is the global ip address, and bypasses the BGW320's firewall.