for ip in xxx.xxx.xxx.xxx yyy.yyy.yyy.yyy zzz.zzz.zzz.zzz .... ; do iptables -t nat -A PREROUTING -p tcp -s $ip -d aaa.aaa.aaa.aaa --dport 3389 -j DNAT --to-destination bbb.bbb.bbb.bbb:33891; done