Configuring Exec Authorization
When RADIUS exec authorization is performed, the RUCKUS device consults a RADIUS server to determine the privilege level of the authenticated user.
To configure RADIUS exec authorization on the RUCKUS device, enter the following command.
device(config)# aaa authorization exec default radius
Note: For the aaa authorization exec
default radius command to work, either the aaa authentication enable default
radius command or the aaa
authentication login privilege-mode command must exist in the configuration.
Note: If the aaa authorization exec default
radius command exists in the configuration, following successful
authentication, the device assigns the user the privilege level specified by the
foundry-privilege-level attribute received from the RADIUS server. If the aaa authorization exec default
radius command does not exist in the configuration, the value in the
foundry-privilege-level attribute is ignored, and the user is granted Super User
access.
If instead you specify aaa authorization exec default none, or omit the aaa authorization exec command from the ICX device configuration, no exec authorization is performed.