I use a dstnat rule in the firewall nat. I route my networks, so this part is easy for me. I will presume the wan interface is Mikrotik 1 on ether1, and the localnet that both Mikrotik routers share is 192.168.1.x/24 and the Mikrotik 2 router is assigned 192.168.1.2/24. In Mikrotik 1, enter this rule:
/ip firewall nat
add chain=dstnat action=dst-nat dst-port=8291 protocol=tcp to-addresses=192.168.1.2 to-ports=8291 in-interface=ether1
When you connect to Miktrotik 1 on port 8291, you will actually connect to Mikrotik 2.
If you want to connect to the core router and a few routers behind the core router, you can enumerate the dst-port values. Use dst-port 8292 for the internal device.
/ip firewall nat
add chain=dstnat action=dst-nat dst-port=8292 protocol=tcp to-addresses=192.168.1.2 to-ports=8291 in-interface=ether1
When you open Winbox, enter the ip:port in the "Connect To" box.
xx.xx.xx.xx:8292