Nick, Mike

It turns out that it was my mistake and "-r" is all that is needed in
RedHat 7.2!

The /etc/sysconfig/syslog file configures TWO utilities - syslogd and
klogd (the kernel log daemon). I had added "-r" to klogd's options
rather than those of syslogd. Sigh!!

Re. your comments about port 514/udp, RedHat 7.2 does block this port by
default in /etc/sysconfig/ipchains; in fact it blocks all UDP ports
below 1024. I believe this default blocking is a feature new to 7.2.

This does not appear to affect logging via syslog when the "-r" option
is used and ipchains does not need to be changed. Note that I did change
ipchains for port 514/udp but backed this off after the "-r" fix and
then restarted ipchains to ensure the status quo ante.

I am happy now that MailScanner logging is working but confused as to
why it is working given Nick's comments and the default filtering of
port 514/udp that is done in RedHat 7.2.

