Just add `-d a.b.c.d` immediately after `tcp`, to restrict the rule to packets with destination address `a.b.c.d`.
And add `-s e.f.g.h` to also restrict by source address.
Just add `-d a.b.c.d` immediately after `tcp`, to restrict the rule to packets with destination address `a.b.c.d`.
And add `-s e.f.g.h` to also restrict by source address.