Wow, you have quite the set up!
Your solution requires a multi-level answer... and I'm afraid I can only easily answer part of it.
For your xbox (and I presume your other game consoles as well) will need to use the advanced outbound NAT setting. Enable that setting, and make some rules similar to this:
| Interface | Source | Destination | Target | Description |
| WAN | 192.168.2.0/24 (your LAN network) | * | * | General LAN |
| WAN | 192.168.2.20/32 (your xbox's IP) | * | *(no portmap) | xBox |
I would also suggest using your unused 3rd interface as the DMZ.