1. Does the server accept TCP connections for syslog? Most setups I have seen used only UDP.
Use below command to verify in the server
~:20> netstat -an | grep "514" | grep LISTEN
*.514 *.* 0 0 49152 0 LISTEN
*.514 *.* 0 0 49152 0 LISTEN
*.514 *.* 0 0 49152 0 LISTEN
2. Check routing between firewall and SYSLOG server
Use ping/traceroute from the firewall
Hope that helps,
Cesar