aaa authorization commands

Configures the AAA authorization configuration parameters for EXEC commands.
Syntax
aaa authorization commands privilege-level default radius [ tacacs+ ] [ none ]
no aaa authorization commands privilege-level default radius [ tacacs+ ] [ none ]
aaa authorization commands privilege-level default tacacs+ [ radius ] [ none ]
no aaa authorization commands privilege-level default tacacs+ [ radius ] [ none ]
aaa authorization commands privilege-level default none
no aaa authorization commands privilege-level default none
Command Default

AAA authorization is not enabled.

Parameters
privilege-level
Configures the device to perform AAA authorization for the commands available at the specified privilege level. Valid values are 0 (Super User level - all commands), 4 (Port Configuration level - port-config and read-only commands), and 5 (Read Only level - read-only commands).
default
Configures the default named list.
radius
Configures RADIUS authorization.
tacacs+
Configures TACACS+ authorization.
none
Disables authorization.
Modes

Global configuration mode

Usage Guidelines

You can configure RADIUS, TACACS+, and None as authorization methods. If the configured primary authorization fails due to an error, the device tries the backup authorization methods in the order they are configured.

When TACACS+ command authorization is enabled, the ICX device consults a TACACS+ server to get authorization for commands entered by the user.

When RADIUS command authorization is enabled, the ICX device consults the list of commands supplied by the RADIUS server during authentication to determine whether a user can issue a command that was entered.

Note: TACACS+ and RADIUS command authorization can be performed only for commands entered from Telnet or SSH sessions, or from the console. No authorization is performed for commands entered at the Web Management Interface.

TACACS+ command authorization is not performed for the following commands:

  • At all levels: exit, logout, end, and quit.
  • At the Privileged EXEC level: enable or enabletext, where text is the password configured for the Super User privilege level.

Because RADIUS command authorization relies on the command list supplied by the RADIUS server during authentication, you cannot perform RADIUS authorization without RADIUS authentication.

The no form of the command disables authorization.

Examples

The following example shows how to configure RADIUS command authorization for the commands available at the Super User privilege level (that is, all commands on the device).

device(config)# aaa authorization commands 0 default radius

The following example shows how to configure TACACS+ command authorization for the commands available at the Super User privilege level (that is, all commands on the device).

device(config)# aaa authorization commands 0 default tacacs+