Found the answer - I need to switch my AT&T box to "IP Passthrough" mode! Then I plug my new router into that AT&T box and my router gets the public/WAN IP and does all the work for handling my home network. FINALLY got rid of that AT&T thing (I hated it - it won't even let you set your own DNS IPs and forces you to use AT&T's - I confirmed that fact with AT&T support)
Here are the details for reconfiguring AT&T box:
https://forums.att.com/conversations/att-internet-equipment/bridgemode-vs-ip-passthrough-setup-information/5defbfffbad5f2f606ad5ed2?source=ESSZ0SSPR00facsEM&wtExtndSource=20190210182827_AT&T%20Fiber%20Equipment_Wireline_LITHIUM_2127251541=#M29310