Configuring Command Authorization

When RADIUS command authorization is enabled, the RUCKUS device consults the list of commands supplied by the RADIUS server during authentication to determine whether a user is allowed to issue a command he or she has entered.

You enable RADIUS command authorization by specifying a privilege level for which commands require authorization.

To configure the RUCKUS device to authorize the commands available at the Super User privilege level (that is, all commands on the device), enter the commands shown in the following example.

device# configure terminal
device(config)# aaa authorization commands 0 default radius

The example sets the privilege level to 0, for Super User authorization, and configures RADIUS authorization.

The privilege-level parameter can be one of the following:

  • 0 - Authorization is performed (that is, the RUCKUS device looks at the command list) for commands available at the Super User level (all commands).
  • 4 - Authorization is performed for commands available at the Port Configuration level (port-config and read-only commands).
  • 5 - Authorization is performed for commands available at the Read Only level (read-only commands).
Note: RADIUS command authorization can be performed only for commands entered from Telnet or SSH sessions, or from the console. No authorization is performed for commands entered at the Web Management Interface.
Note: Since RADIUS command authorization relies on the command list supplied by the RADIUS server during authentication, you cannot perform RADIUS authorization without RADIUS authentication.