TACACS+ Authorization

RUCKUS devices support two kinds of TACACS+ authorization:

  • Exec authorization determines a user privilege level when a user is authenticated.
  • Command authorization consults a TACACS+ server to obtain authorization for commands entered by the user.

When TACACS+ exec authorization takes place, the following events occur.

  1. A user logs into the RUCKUS device using Telnet, SSH, or the Web Management Interface.
  2. The user is authenticated.
  3. The RUCKUS device consults the TACACS+ server to determine the privilege level of the user.
  4. The TACACS+ server sends back a response containing an A-V (Attribute-Value) pair with the privilege level of the user.
  5. The user is granted the specified privilege level.

When TACACS+ command authorization takes place, the following events occur.

  1. A Telnet, SSH, or Web Management Interface user previously authenticated by a TACACS+ server enters a command on the RUCKUS device.
  2. The RUCKUS device looks at its configuration to see if the command is at a privilege level that requires TACACS+ command authorization.
  3. If the command belongs to a privilege level that requires authorization, the RUCKUS device consults the TACACS+ server to see if the user is authorized to use the command.
  4. If the user is authorized to use the command, the command is executed.