Port forwarding WAN-IP:1234 to LAN-IP:4321 won't work

It depends.

For srcnat, if it’s supposed to be protection against bouncing spoofed packets from WAN back to internet, with your router as new source, it’s not the best one. Such packets can easily have 192.168.1.x as source. It doesn’t hurt, but I’d rather block them in “/ip firewall filter”. Not that it would concern you much, when the router is behind NAT.

For dstnat, src-address=192.168.1.0/24 won’t work well for connections from internet, unless your Asus router also has such broad masquerade as you had, which it most likely doesn’t. And in-interface=WAN generally also isn’t the best, because it breaks connections to public address from LAN (hairpin NAT). But again, not a problem in your case with router behind NAT. If you’d need that, either the Asus would do what’s needed, or you’d need another dstnat rule anyway.