ok one of my buddies on IRC said its def possible....

his answer is NAT to quote
<Anti-Hero> box2.doman.org resolves to pub IP which is then NAT to internal
addy., firewall rules port forward to 22. box2.domain.com
resolves to pub IP which is NAT to internal addy.

he will explain it more sometime tonight or tomorrow when we both have time