Why would you create a global
(TCP, Outbound, Remote Host: 127.0.0.1, Remote Port: 12080, Allow)
rule? You should simply allow to connect to 127.0.0.1:12080 only to those apps that you’d normally allow to connect to the Internet on port 80.