WAN configuration won't make a difference - the router handles that. Be sure that the WLAN is on the same native network as the LAN port on the router and that the IP address block the radio gets is the same as the laptop. Assign a STATIC IP to the laptop LAN port.
Then, TURN OFF the useless software Windows Firewall on the laptop as it causes issues. Be sure the connection type is Private, not Public on the computer. Or, be sure that UDP 5353 is allowed inbound on the laptop.
Install DDNS and MNIS on the laptop (not always necessary, but install it now just to be sure). If everything (RM Server, Job processor, device monitor, SQLExpress) is on the same computer, localhost is perfectly fine.
Go into the radio codeplug (use CPS2 if necessary over USB) and set the Wi-Fi Network -> General -> DNS-SD interval to 90s, DNS-SD Listening Port to 5353 -> Device Discovery Server Name to the (static) IP of the laptop.
Go to the RM Server Configuration, be sure that Machine Authorization is enabled and the laptop (by name) has "Device Programmer" and "Job Processor" checked. Also, be sure User Authorization has a Non-Domain user added for both RM Administrator and RM Client User (make a new Non-Domain account by hitting the + and keep it simple for now - user "moto", password "password".
Go into Job Processor and Device Monitor. Click the Test Connection button. If it doesn't connect, choose "One-Time Password" and use the account you created. It'll switch to Certificate after a successful validation.
In Device Monitor, also be sure the DNS-SD Listening port is 5353, the communication method is "USB" AND "Wireless (LAN)". Don't check OTA or IP.
Be sure that the radio is on the new(er)(est) firmware - ideally at the same level as the RM install. If the FW is too old, it can do really stupid things.
Restart computer, wait about 2 minutes, and it should program.