Ken, I'm using a RB951Ui-2HnD model. Below is my exported configuration.
Particularly, this is the action that configures the NAT:
add action=dst-nat chain=dstnat protocol=tcp src-address=10.36.25.100 to-addresses=192.168.1.10
[admin@Cooper SAP nest] > /export
# dec/04/2019 06:46:37 by RouterOS 6.39.2
# software id = MSC1-EN70
#
/interface bridge
add name=Bridge
add admin-mac=64
1:54:E7:52:83 auto-mac=no comment=defconf name=bridge
/interface ethernet
set [ find default-name=ether2 ] name=ether2-master
set [ find default-name=ether3 ] master-port=ether2-master
set [ find default-name=ether4 ] master-port=ether2-master
set [ find default-name=ether5 ] master-port=ether2-master
/ip neighbor discovery
set ether1 discover=no
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
add authentication-types=wpa2-psk mode=dynamic-keys name=CSD wpa2-pre-shared-key=Scannr@Prod
/interface wireless
set [ find default-name=wlan1 ] band=2ghz-b/g/n channel-width=20/40mhz-Ce country="united states3" disabled=no distance=indoors frequency=auto mode=station-pseudobridge security-profile=CSD ssid=CS-DATA wireless-protocol=802.11
/interface bridge port
add bridge=bridge comment=defconf interface=ether2-master
add bridge=bridge comment=defconf interface=wlan1
/ip dhcp-client
add comment=defconf dhcp-options=hostname,clientid disabled=no interface=bridge
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=192.168.88.1 name=router
/ip firewall filter
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment="defconf: accept established,related" connection-state=established,related
add action=drop chain=input comment="defconf: drop all from WAN" in-interface=ether1
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related
add action=accept chain=forward comment="defconf: accept established,related" connection-state=established,related
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface=ether1
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" disabled=yes out-interface=all-ethernet
add action=dst-nat chain=dstnat protocol=tcp src-address=10.36.25.100 to-addresses=192.168.1.10
/system clock
set time-zone-name=EST
/system identity
set name="Cooper SAP nest"
/system ntp client
set enabled=yes primary-ntp=192.168.104.69
/system routerboard settings
set init-delay=0s
/tool mac-server
set [ find default=yes ] disabled=yes
add interface=bridge
/tool mac-server mac-winbox
set [ find default=yes ] disabled=yes
add interface=bridge