Redirection alone is half the story. The redirected traffic must be allowed to continue on to the destination. This will usually work (assuming the target is behind another interface):
Code:
(this takes care of the 'pass in' part on the external side)
rdr pass on $ext_if inet proto tcp from any to $ext_if port 3133 -> 192.168.1.133 port 3389
rdr pass on $ext_if inet proto tcp from any to $ext_if port 3130 -> 192.168.1.130 port 3389
(this will take care of the 'pass out' part on the internal side)
pass out quick on $int_if inet proto tcp from any to 192.168.1.133 port 3389 keep state
pass out quick on $int_if inet proto tcp from any to 192.168.1.130 port 3389 keep state
etc.