I'm not quite sure about the capabilities of the switch, but I could think of a simple issue with tagging the packets on both ends, on the port group as well as on the physical switch port!? Basically you should either configure access ports for the appropriate VLAN without VLAN tagging on the port group, or configure trunk ports (with the appropriate VLANs allowed) and do the VLAN tagging on the port group. The latter is what I usually do, configuring all the physical switch ports as trunk ports and do the complete VLAN tagging on the virtual port groups. IMO this makes networking easy and avoids confusion.
André