Just don't try and use kickstart with RHEL AS 3 Update 2 - there is apparantly a known bug that causes any kickstart script with a firewall line to fail.
So you have to _not_ install the firewall setup you want, and also in %post do
chkconfig iptables off
otherwise you won't be able to ssh into the machine once it's installed.
Once it's installed you then have to do a manual firewall setup. There will apparantly be a fix in update 3.
This is what you pay a grand for support for
One of the biggest problems you'll run into with traditional Unix shops is that kickstart requires some kind of network service to install from, like NFS or FTP. Things like Jumpstart (Sun) don't need this as the file deployment is built into the tool. I'm seeing some resistance on this topic.