We are really struggling to get our SnoLo server's SUS to contact the Apple update servers - for some reason SUS does not use the system proxy settings - Apple have a work around (http://support.apple.com/kb/TS3099) whereby you enter your proxy settings in the swsync plist.
However this doesn't work for us and it wasn't a problem with our 10.5 servers either.
In the KB article Apple helpfully suggests that we reconfigure our firewall rules to allow the server to have direct internet access, amazingly the guardian of our firewall rules is not so keen on the idea!