U mnie dziala taka regula
iptables -t nat -A PREROUTING -s $INTNETSHORT$user -p = tcp -d ! $INTNETSHORT$user --dport 1:65535 -j DNAT = --to-destination 192.168.0.1:200