TACACS+ Authorization
RUCKUS devices support two kinds of TACACS+ authorization:
- Exec authorization determines a user privilege level when a user is authenticated.
- Command authorization consults a TACACS+ server to obtain authorization for commands entered by the user.
When TACACS+ exec authorization takes place, the following events occur.
- A user logs into the RUCKUS device using Telnet, SSH, or the Web Management Interface.
- The user is authenticated.
- The RUCKUS device consults the TACACS+ server to determine the privilege level of the user.
- The TACACS+ server sends back a response containing an A-V (Attribute-Value) pair with the privilege level of the user.
- The user is granted the specified privilege level.
When TACACS+ command authorization takes place, the following events occur.
- A Telnet, SSH, or Web Management Interface user previously authenticated by a TACACS+ server enters a command on the RUCKUS device.
- The RUCKUS device looks at its configuration to see if the command is at a privilege level that requires TACACS+ command authorization.
- If the command belongs to a privilege level that requires authorization, the RUCKUS device consults the TACACS+ server to see if the user is authorized to use the command.
- If the user is authorized to use the command, the command is executed.