I seek a prosumer router, something similar to UniFi Dream Machine, but with newer hardware for WireGuard throughput and better customizations. For example, I want to be able to access router via SSH to not only customize NAT via IPTables, but have my rules preserved after reboot and not have router override my settings or remove my tables when making further changes in router GUI, which is known as reprovisioning. Current routers like UniFi Dream Machine strip many custom settings during such a reprovisioning process and require 3rd party on-boot scripts to force custom changes during boot, but such scripts are not good enough because timing of application of custom settings is important or else GUI-based rules and custom rules mess up.
Manual SSH customization shouldn't even be necessary if router makers included all the necessary features in GUI. For example, some current ASUS routers let you create VLAN's, but do not allow creation of specific NAT rules for them. They only allow creation of NAT rules for man LAN. You need Merlin firmware with custom script applicaiton to get around that.
DD-WRT and OpenWRT are awesome, but router makers now focus on Secure Boot and make it impossible for newer models to support DD-WRT and OpenWRT. I know there is pfSense, but it is too much for me.
RouterOS seems to do all I want, I think... I'd like to try it, but I don't understand MikroTik products. Many MirkoTik products are labeled as Access Point, but do they include router capabilities? I see topics discussing how a user can simply designate one of AP Ethernet ports to be a WAN port. If that can do be done, then how are MikroTik AP's different from AIO Router+AP solutions? For example, https://mikrotik.com/product/chateau_lte12 is "one router to delight them all", but description is one of an AP, not a router. I am OK with spending time learning how to use MirkoTik AP products and RouterOS, but I want to make sure they can function as actual routers.