Configuring Exec Authorization

When TACACS+ exec authorization is performed, the RUCKUS device consults a TACACS+ server to determine the privilege level of the authenticated user. To configure TACACS+ exec authorization on the RUCKUS device, enter the following command.

device(config)# aaa authorization exec default tacacs+

If you specify none or omit the aaa authorization exec command from the device configuration, no exec authorization is performed.

Note: The TACACS+ server is a separate device made by third-party manufacturers. It is used to authenticate clients logging into the RUCKUS device using telnet, SSH, or console. There are multiple applications available for configuring TACACS+ servers, such as tac_plus for Linux and Cisco ACS for Windows. RUCKUS recommends setting the client user's "privlvl" attribute to 15 because this assigns super-user privileges to the authenticated client. If the "privlvl" attribute is not available under the user configuration options for your TACACS+ server software, refer to the TACACS+ server’s support documentation.
Note: If the aaa authorization exec default tacacs+ command exists in the configuration, following successful authentication, the device assigns the user the privilege level specified by the "foundry-privlvl" A-V pair received from the TACACS+ server. If the aaa authorization exec default tacacs+ command does not exist in the configuration, the value in the "foundry-privlvl" A-V pair is ignored, and the user is granted Super User access.
Note: For the aaa authorization exec default tacacs+ command to work, either the aaa authentication enable default tacacs+ command or the aaa authentication login privilege-mode command must also exist in the configuration.

Configuring an Attribute-Value Pair on the TACACS+ Server

During TACACS+ exec authorization, the RUCKUS device expects the TACACS+ server to send a response containing an A-V (Attribute-Value) pair that specifies the privilege level of the user. When the RUCKUS device receives the response, it extracts an A-V pair configured for the Exec service and uses it to determine the user privilege level.

To set a user privilege level, you can configure the "foundry-privlvl" A-V pair for the Exec service on the TACACS+ server. Consider the following TACACS+ server configuration.

user=bob {
   default service = permit
   member admin
   #Global password
   global = cleartext "cat"
   service = exec {
     foundry-privlvl = 0
        }
}

In the previous example, the A-V pair foundry-privlvl = 0 grants the user full read-write access. The value in the foundry-privlvl A-V pair is an integer that indicates the privilege level of the user. Possible values are 0 for super-user level, 4 for port-config level, or 5 for read-only level. If a value other than 0, 4, or 5 is specified in the foundry-privlvl A-V pair, the default privilege level of 5 (read-only) is used. The foundry-privlvl A-V pair can also be embedded in the group configuration for the user. Refer to TACACS+ documentation for the configuration syntax relevant to your server.

If the foundry-privlvl A-V pair is not present, the RUCKUS device extracts the last A-V pair configured for the Exec service that has a numeric value and uses this A-V pair to determine the user privilege level.

Consider the following TACACS+ server configuration.

user=bob {
   default service = permit
   member admin
   #Global password
   global = cleartext "cat"
   service = exec {
     privlvl = 15
        }
}

In the example, the attribute name in the A-V pair is not significant; the RUCKUS device uses the last one that has a numeric value. However, the RUCKUS device interprets the value for a non-"foundry-privlvl" A-V pair differently than it does for a "foundry-privlvl" A-V pair. The following table lists how the RUCKUS device associates a value from a non-"foundry-privlvl" A-V pair with a RUCKUS privilege level.

RUCKUS Equivalents for Non-"foundry-privlvl" A-V Pair Values

Value for Non-"foundry-privlvl" A-V Pair

RUCKUS Privilege Level

15

0 (super-user)

From 14 - 1

4 (port-config)

Any other number or 0

5 (read-only)

In the previous example, the A-V pair configured for the Exec service is privlvl = 15. The RUCKUS device uses the value in this A-V pair to set the user privilege level to 0 (super-user), granting the user full read-write access.

In a configuration that has both a "foundry-privlvl" A-V pair and a non-"foundry-privlvl" A-V pair for the Exec service, the non-"foundry-privlvl" A-V pair is ignored.

Consider the following TACACS+ server configuration.

user=bob {
   default service = permit
   member admin
   #Global password
   global = cleartext "cat"
   service = exec {
     foundry-privlvl = 4
     privlvl = 15
        }
}

In the previous example, the user would be granted a privilege level of 4 (port-config level). The privlvl = 15 A-V pair is ignored by the RUCKUS device.

If the TACACS+ server has no A-V pair configured for the Exec service, the default privilege level of 5 (read-only) is used.