There is currently no firewall ruleset on that interface and no reference to that /24 anywhere else in the router config.
I can delete eth2.88, assign 10.0.10.1/24 as a secondary address on eth2, remove the VLAN tag from the VM network options, start the VM, and it will ping the router interface.