You also need to tell the Heavy Forwarder to listen on port 9997 (or whatever you choose). They didn't include this step in the instructions to setup a heavy forwarder, but you can find it here:
https://docs.splunk.com/Documentation/Splunk/7.3.1/Forwarding/Enableareceiver
... View more