This solution works for me:
iptables -t nat -A PREROUTING -i vmbr0 -p tcp -d HOST.PUBLIC.IP.ADDRESS -j MARK --set-mark 0x200/0x200
iptables -t nat -A PREROUTING -i vmbr0 -p tcp -d HOST.PUBLIC.IP.ADDRESS -j DNAT --to IP.ADDRESS.OF.VMBR0
iptables -t nat -A POSTROUTING -o vmbr0 -m mark --mark 0x200...