How to allow a user to access an internal machine using pf.conf

Using pf, describe (or write the rules for) a firewall setup that will allow a remote user to access a particular internal machine from an external ip address specified within the ruleset itself.

How do I specify in the ruleset inside the pf.conf to allow an external user to remotely access the internal machine considering his ip is specified inside the ruleset.