aaa authorization exec
aaa authorization exec
default
radius
[tacacs+
]
[
none
]no aaa authorization
exec
default
radius
[
tacacs+
]
[
none
]aaa authorization exec
default
tacacs+
[
radius
]
[
none
]no aaa authorization
exec
default
tacacs+
[
radius
]
[
none
]aaa authorization exec
default
noneno aaa authorization
exec
default
noneAAA authorization is not configured.
Global configuration mode
You can configure RADIUS, TACACS+, and None as authorization methods. If the configured primary authorization fails due to an error, the device tries the backup authorization methods in the order they are configured.
The aaa authorization exec
default
tacacs+ command must be configured before the aaa authentication
login
default
tacacs+ command or the aaa authentication
enable
default
tacacs+ command can be configured. If you attempt to configure
either of these commands first, the following message is displayed: Warning- Please configure exec
authorization using TACACS+ to get user privilege.
When TACACS+ EXEC authorization is performed,
the ICX device consults a TACACS+ server to determine the privilege level of the
authenticated user. If the aaa authorization exec
default
tacacs+ command exists in the configuration, following
successful authentication, the device assigns the user the privilege level specified
by the foundry-privilege-level received from the TACACS+ server. If the aaa authorization exec
default
tacacs+ command does not exist in the configuration, the value
in the foundry-privilege-level attribute is ignored, and the user is granted Super
User access. Also note that in order for the aaa authorization exec
default
tacacs+ command to work, either the aaa authentication
enable
default
tacacs+ command, or the aaa authentication
login
default
local command must also exist in the configuration.
When RADIUS EXEC authorization is performed, the
ICX device consults a RADIUS server to determine the privilege level of the
authenticated user. If the aaa authorization exec
default
radius command exists in the configuration, following
successful authentication, the device assigns the user the privilege level specified
by the foundry-privilege-level attribute received from the RADIUS server. If
the
aaa authorization exec
default radius command does not exist in the
configuration, the value in the foundry-privilege-level attribute is ignored,
and
the user is granted Super User access. Also note that in order for the aaa authorization exec
default
radius command to work, either the aaa authentication
enable
default
radius command, or the aaa authentication
login
default
local command must also exist in the configuration.
The following example shows how to configure TACACS+ EXEC authorization.
device(config)# aaa authorization exec default tacacs+
The following example shows how to configure RADIUS EXEC authorization.
device(config)# aaa authorization exec default radius