ethernet over IP


I'm planning on creating some of the IPSec bridges to extend our server
network into multiple places for better redundancy.  I have a few 

Can the internal ethernet interface be part of a tagged VLAN, and if 
so how do you use it in the configuration?

For routing, would it be normal to give the internal ethernet interface
an IP address and have the clients in the same physical area route
through it?

We have private IP addresses on the external interface and we will
currently do this all on a network where those IP addresses are
routable.  Would it be possible to extend that network at some point in
time to work over the internet by using a VPN to tunnel the private IP
addresses and then creating a bridge?