Configuring Exec Authorization

When RADIUS exec authorization is performed, the RUCKUS device consults a RADIUS server to determine the privilege level of the authenticated user.

To configure RADIUS exec authorization on the RUCKUS device, enter the following command.

device(config)# aaa authorization exec default radius
Note: For the aaa authorization exec default radius command to work, either the aaa authentication enable default radius command or the aaa authentication login privilege-mode command must exist in the configuration.
Note: If the aaa authorization exec default radius command exists in the configuration, following successful authentication, the device assigns the user the privilege level specified by the foundry-privilege-level attribute received from the RADIUS server. If the aaa authorization exec default radius command does not exist in the configuration, the value in the foundry-privilege-level attribute is ignored, and the user is granted Super User access.

If instead you specify aaa authorization exec default none, or omit the aaa authorization exec command from the ICX device configuration, no exec authorization is performed.