Configuring Command Authorization
When RADIUS command authorization is enabled, the RUCKUS device consults the list of commands supplied by the RADIUS server during authentication to determine whether a user is allowed to issue a command he or she has entered.
You enable RADIUS command authorization by specifying a privilege level for which commands require authorization.
To configure the RUCKUS device to authorize the commands available at the Super User privilege level (that is, all commands on the device), enter the commands shown in the following example.
device# configure terminal device(config)# aaa authorization commands 0 default radius
The example sets the privilege level to 0, for Super User authorization, and configures RADIUS authorization.
The privilege-level parameter can be one of the following:
- 0 - Authorization is performed (that is, the RUCKUS device looks at the command list) for commands available at the Super User level (all commands).
- 4 - Authorization is performed for commands available at the Port Configuration level (port-config and read-only commands).
- 5 - Authorization is performed for commands available at the Read Only level (read-only commands).