well VRF-lite is something locally significant to the device not something you pass over the WAN links either L3 or L2
it can be done back to back VRF-lite links per interface or subinterface
or it can be fully virtualized end to end VRFs over MP-BGP L3 VPN with MPLS
in you case if you want to have per customer VRF-lite then you might have a subinterface in differnt VLAN to be assigned to a certain VRF and you can run do same concept in the other end with runing a routing istnace per VRF
or you can use it with MPLS over GRE tunnel but the limitation is that 3560 dose not support GRE tunneling although you can configure it but it is not a feature supported by Cisco Cat switches except 6500
Hope this help
if helpful Rate