Can the log host accept connections from the Firebox?
WatchGuard logging uses TCP port 4107. If the log host has a software-based firewall installed, there must be an exception in the firewall settings that allows the log host to accept connections over TCP port 4107 from the Firebox IP address. For the Windows Firewall included with Windows XP SP2, you can add an exception by application name or by port. To add an exception to the Windows Firewall for an application, click on the Windows Firewall Exceptions tab, and then click on the Add Program button. Finally, browse to the directory where you installed the WatchGuard software. Add an exception for controld.exe.