This answer is highly dependent on a few factors.
- Source IP or Network
- Destination IP or Network
- Currently configured ACL entries, if any (for ordering)
- whether NAT is being used
However, in its most simple form..
ip access-list extended <acl_name>
permit tcp <source> <destination> eq 3389
interface <interface name>
ip access-group <acl_name> <direction (in/out)>
I would recommend reviewing some Cisco documentation before proceeding.
https://www.cisco.com/c/en/us/support/docs/security/ios-firewall/23602-confaccesslists.html