anonymous access needs to be set in two places.
First at the Web Application level under Authentication Providers I think
And then at the site where you want to enable anonomous access.
I currently don't have a MOSS lab to validate the location where you set it but I think that's pretty close.