NAT question

I am having a problem with using one mikrotik for multiple functions. Here is the config.

Interfaces:
“Ethernet LAN”
“WirlesaAP” (ap bridge mode)
“wds1"”
“wds2”

Bridge: “Wireless-Bridge”
“WirelessAP”
“wds1”
“wds2”


NAT setup
IP → firewall → NAT

Chain: “srcnat”
Out Interface: “Wireless-Bridge”
Action: “masquerade”

Description:
The local interface works fine.
When I am on the other side of the AP - the other mikrotik “wds2” it will masquerade that traffic also. What I want is the local traffic to be masqueraded not the Wireless.

Let me know if this makes since.

Every NAT (firewall) rule has too many parameters to determine, which traffic to masquerade, and which not.